๐Ÿ” CVE Alert

CVE-2026-54724

MEDIUM 6.1

Kiwi TCMS: Open Redirect via unvalidated next parameter in account confirmation endpoint

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external domain. The trusted origin can support credential-harvesting pages, bypass email security filters and link-reputation checks that allowlist the organization's domain, or deliver malware through a convincing account-confirmation lure. This issue is fixed in version 16.1.

CWE CWE-601
Vendor kiwitcms
Product kiwi
Published Sep 15, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for kiwitcms kiwi

Be the first to know when new medium vulnerabilities affecting kiwitcms kiwi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

kiwitcms / Kiwi
< 16.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-hmj5-jm8h-h9fh github.com: https://github.com/kiwitcms/Kiwi/commit/93fe8bb94dd79212fda9a1d5aa6db8594d0b4e06 github.com: https://github.com/kiwitcms/Kiwi/releases/tag/v16.1