
Critical Vulnerabilities Discovered in Redmine Allowing XSS and Security Bypass
CybersecurityVulnerabilitiesSoftwareSecurityExploits
Multiple vulnerabilities were discovered in Redmine on 26 August 2026, as reported by CERT-FR. These flaws enable attackers to execute remote indirect code injection (XSS) and bypass security policies. The advisory specifies no CVE identifiers, affected versions, or additional technical details beyond the attack vectors. The impacts include potential unauthorized code execution and circumvention of security controls within the application. No information regarding exploitation in the wild or mitigation steps is provided in the notice.