{"id":"CVE-2026-54724","title":"Kiwi TCMS is an open source test management system","summary":"Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redire…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-601"],"vendor":"kiwitcms","product":"Kiwi","affected":["Kiwi < 16.1"],"published":"2026-09-15","updated":"2026-09-15","sourceUpdated":"2026-09-15T17:17:21.383","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54724","references":[{"url":"https://github.com/kiwitcms/Kiwi/commit/93fe8bb94dd79212fda9a1d5aa6db8594d0b4e06","label":"security-advisories@github.com"},{"url":"https://github.com/kiwitcms/Kiwi/releases/tag/v16.1","label":"security-advisories@github.com"},{"url":"https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-hmj5-jm8h-h9fh","label":"security-advisories@github.com"},{"url":"https://kiwitcms.org/blog/kiwi-tcms-team/2026/06/24/kiwi-tcms-161"},{"url":"https://github.com/advisories/GHSA-hmj5-jm8h-h9fh"}],"tags":["nvd","cve.org","ghsa","pip"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T16:53:12.255993Z"},"aliases":["GHSA-hmj5-jm8h-h9fh"],"ecosystem":"pip","ingestedAt":"2026-07-06T21:45:52.927Z","epss":0.0026,"epssPercentile":0.18024,"slug":"CVE-2026-54724","body":"## Overview\n\nKiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external domain. The trusted origin can support credential-harvesting pages, bypass email security filters and link-reputation checks that allowlist the organization's domain, or deliver malware through a convincing account-confirmation lure. This issue is fixed in version 16.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-54724)\n\nAffected packages:\n\n- `kiwitcms <= 112.4`\n\nSource: https://github.com/advisories/GHSA-hmj5-jm8h-h9fh","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}