VulnerabilityDeferred
CVE-2026-1836
This could allow an attacker with access to the platform to return to the browser and view the login credentials.
MEDIUM 5.3EPSS 0.10%
Does this matter?
Lower severity and a low EPSS score (0.10%). Track it; it rarely justifies an emergency change on its own.
Description
The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.10% probability · 1th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-257
- Source
- cve-coordination@incibe.es
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.