๐Ÿ” CVE Alert

CVE-2026-49292

UNKNOWN 0.0

Kiwi TCMS: The /init-db/ page renders and responds to requests after first use

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migrate. The migration command is reentrant, so repeated access reports that no migrations are available and does not cause data loss, alter application state, reveal confidential information, or produce a documented availability impact. This issue is fixed in version 16.0.

CWE CWE-862
Vendor kiwitcms
Product kiwi
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for kiwitcms kiwi

Be the first to know when new unknown vulnerabilities affecting kiwitcms kiwi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
None

Affected Versions

kiwitcms / Kiwi
< 16.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-v8rp-6xcv-fwgh github.com: https://github.com/kiwitcms/Kiwi/pull/4364 github.com: https://github.com/kiwitcms/Kiwi/commit/d364ec47ec5a77b98bad2ab702b0406075a0e081 github.com: https://github.com/kiwitcms/Kiwi/releases/tag/v16.0 kiwitcms.org: https://kiwitcms.org/blog/kiwi-tcms-team/2026/06/05/kiwi-tcms-160