Open Source Test Management System Vulnerability in Kiwi TCMS
CVE-2026-54724
6.1MEDIUM
What is CVE-2026-54724?
Kiwi TCMS, an open source test management system, contains a vulnerability where its account confirmation endpoint accepts an unvalidated 'next' parameter. This allows unauthenticated attackers to craft URLs on the trusted Kiwi TCMS domain to redirect victims to arbitrary external websites. Such redirects can lead to credential harvesting, phishing attempts, and malware distribution, as attackers can bypass email security filters and link reputation checks. The issue has been addressed in version 16.1, making it crucial for users to update their installations to mitigate these risks.
Affected Version(s)
Kiwi < 16.1
