Open Source Test Management System Vulnerability in Kiwi TCMS
CVE-2026-54724

6.1MEDIUM

Key Information:

Vendor

Kiwitcms

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-54724?

Kiwi TCMS, an open source test management system, contains a vulnerability where its account confirmation endpoint accepts an unvalidated 'next' parameter. This allows unauthenticated attackers to craft URLs on the trusted Kiwi TCMS domain to redirect victims to arbitrary external websites. Such redirects can lead to credential harvesting, phishing attempts, and malware distribution, as attackers can bypass email security filters and link reputation checks. The issue has been addressed in version 16.1, making it crucial for users to update their installations to mitigate these risks.

Affected Version(s)

Kiwi < 16.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.