Description
Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migrate. The migration command is reentrant, so repeated access reports that no migrations are available and does not cause data loss, alter application state, reveal confidential information, or produce a documented availability impact. This issue is fixed in version 16.0.
Published: 2026-09-17
Score: 0 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to init-db endpoint (no data loss)
Action: Assess Impact
AI Analysis

Impact

Kiwi TCMS exposes an /init-db/ web page that, after the first database setup, remains reachable without authentication. The page forwards every request to the Django migrate command, which is re‑entrant; therefore repeated accesses merely report that no migrations are pending and neither alter the database state nor leak sensitive data. Consequently, the vulnerability is a missing authorization flaw (CWE‑862) that does not allow data loss, privilege escalation, or service disruption, although an attacker can discover that the endpoint exists.

Affected Systems

All installations of Kiwi TCMS older than version 16.0 are affected. The vulnerability was fixed in release 16.0 of the open‑source Kiwi TCMS management suite.

Risk and Exploitability

The EPSS probability is reported as less than 1 %, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need only unauthenticated reach to the web server to access the /init-db/ page; no additional credentials, network privileges or application state changes are required. Because the endpoint merely reports that no migrations remain and does not modify data, the overall risk and impact for confidentiality, integrity, and availability are negligible, but the exposed endpoint remains an unnecessary attack surface.

Generated by OpenCVE AI on September 19, 2026 at 02:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Kiwi TCMS version 16.0 or later to close the unauthenticated /init-db/ endpoint.
  • If upgrading is not immediately possible, configure the web server or application firewall to block or require authentication for the /init-db/ URL.
  • Review system logs to ensure no unauthorized access attempts are occurring to the /init-db/ page after deploying the fix.

Generated by OpenCVE AI on September 19, 2026 at 02:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-v8rp-6xcv-fwgh Kiwi TCMS's /init-db/ page renders and responds to requests after first use
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Kiwitcms
Kiwitcms kiwi Tcms
Vendors & Products Kiwitcms
Kiwitcms kiwi Tcms

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migrate. The migration command is reentrant, so repeated access reports that no migrations are available and does not cause data loss, alter application state, reveal confidential information, or produce a documented availability impact. This issue is fixed in version 16.0.
Title Kiwi TCMS: The /init-db/ page renders and responds to requests after first use
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N'}


Subscriptions

Kiwitcms Kiwi Tcms
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:11:15.766Z

Reserved: 2026-05-28T20:07:58.862Z

Link: CVE-2026-49292

cve-icon Vulnrichment

Updated: 2026-09-17T19:11:10.589Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T19:16:48.960

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-49292

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:45:16Z

Weaknesses