Description
Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external domain. The trusted origin can support credential-harvesting pages, bypass email security filters and link-reputation checks that allowlist the organization's domain, or deliver malware through a convincing account-confirmation lure. This issue is fixed in version 16.1.
Published: 2026-09-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open redirect that can be used for phishing or malware delivery
Action: Patch immediately
AI Analysis

Impact

Kiwi TCMS is an open source test management system. Prior to version 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external domain. This is a CWE-601 open redirect vulnerability, where the unvalidated next parameter permits arbitrary redirection. The trusted origin can support credential‑harvesting pages, bypass email security filters and link‑reputation checks that allowlist the organization’s domain, or deliver malware through a convincing account-confirmation lure. This issue is fixed in version 16.1.

Affected Systems

The flaw exists in all Kiwi TCMS installations running versions before 16.1. The affected vendor is Kiwi. Updating to version 16.1 or later eliminates the issue.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium severity impact. The EPSS score of < 1% indicates a very low exploitation probability. The vulnerability is not listed in CISA KEV. Attackers only need to craft a malicious link; no authentication is required. The likely attack vector is a crafted email or web link that directs a victim’s browser to the trusted Kiwi TCMS host, which then redirects them to an attacker-controlled site.

Generated by OpenCVE AI on September 20, 2026 at 16:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to version 16.1 or later.
  • Verify that the "next" parameter is validated or removed from the account confirmation flow.
  • If an upgrade is unavailable, restrict the acceptable values of "next" to trusted internal domains or disable external redirects in the account confirmation process.

Generated by OpenCVE AI on September 20, 2026 at 16:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hmj5-jm8h-h9fh Kiwi TCMS has an Open Redirect via unvalidated next parameter in account confirmation endpoint
History

Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external domain. The trusted origin can support credential-harvesting pages, bypass email security filters and link-reputation checks that allowlist the organization's domain, or deliver malware through a convincing account-confirmation lure. This issue is fixed in version 16.1.
Title Kiwi TCMS: Open Redirect via unvalidated next parameter in account confirmation endpoint
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T16:56:25.815Z

Reserved: 2026-06-15T23:07:33.232Z

Link: CVE-2026-54724

cve-icon Vulnrichment

Updated: 2026-09-15T16:56:21.887Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T16:17:14.417

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-54724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')