CVE-2026-49292
Kiwi TCMS: The /init-db/ page renders and responds to requests after first use
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migrate. The migration command is reentrant, so repeated access reports that no migrations are available and does not cause data loss, alter application state, reveal confidential information, or produce a documented availability impact. This issue is fixed in version 16.0.
| CWE | CWE-862 |
| Vendor | kiwitcms |
| Product | kiwi |
| Published | Sep 17, 2026 |
| Last Updated | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for kiwitcms kiwi
Be the first to know when new unknown vulnerabilities affecting kiwitcms kiwi are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
None
Affected Versions
kiwitcms / Kiwi
< 16.0
References
github.com: https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-v8rp-6xcv-fwgh github.com: https://github.com/kiwitcms/Kiwi/pull/4364 github.com: https://github.com/kiwitcms/Kiwi/commit/d364ec47ec5a77b98bad2ab702b0406075a0e081 github.com: https://github.com/kiwitcms/Kiwi/releases/tag/v16.0 kiwitcms.org: https://kiwitcms.org/blog/kiwi-tcms-team/2026/06/05/kiwi-tcms-160