{"id":"CVE-2026-54724","summary":"Kiwi TCMS: Open Redirect via unvalidated next parameter in account confirmation endpoint","details":"Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external domain. The trusted origin can support credential-harvesting pages, bypass email security filters and link-reputation checks that allowlist the organization's domain, or deliver malware through a convincing account-confirmation lure. This issue is fixed in version 16.1.","aliases":["GHSA-hmj5-jm8h-h9fh","PYSEC-2026-2552"],"modified":"2026-09-17T03:45:21.392798712Z","published":"2026-09-15T15:34:26.102Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-601"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54724.json"},"references":[{"type":"WEB","url":"https://github.com/kiwitcms/Kiwi/releases/tag/v16.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54724.json"},{"type":"ADVISORY","url":"https://github.com/kiwitcms/Kiwi/security/advisories/GHSA-hmj5-jm8h-h9fh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54724"},{"type":"FIX","url":"https://github.com/kiwitcms/Kiwi/commit/93fe8bb94dd79212fda9a1d5aa6db8594d0b4e06"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kiwitcms/kiwi","events":[{"introduced":"0"},{"fixed":"93fe8bb94dd79212fda9a1d5aa6db8594d0b4e06"},{"fixed":"e77a0ccc56258e107063a5745fad87cd1461f3a0"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"16.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v15.4","v15.3","v15.2","v15.1","v15.0","v14.3","v14.2","v14.1","v14.0","v13.7","v13.6","v13.5","v13.4","v13.3","v13.2","v13.1.1","v13.1","v13.0","v12.7","v12.6.1","v12.6","v12.5","v12.4","v12.3","v12.2","v12.1","v12.0","v11.7","v11.6","v11.5","v11.4","v11.3","v11.2","v11.1","v11.0","v10.5","v10.4","v10.3","v10.2","v10.1","v10.0","v9.0.1","v9.0","v8.9","v8.8","v8.7","v8.6.1","v8.6","v8.5","v8.4","v8.3","v8.2","v8.1","v8.0","v7.3","v7.2.1","v7.2","v7.1","v7.0","v6.11","v6.10","v6.9","v6.8","v6.7","v6.6","tcms-api-5.3","v6.5.3","v6.5.2","v6.5.1","tcms-api-5.2","tcms-api-5.1","v6.4","v6.3","v6.2.1","v6.2","v6.1.1","v6.1","v6.0.1","v6.0","v5.3.1","v5.3","v5.2","v5.1","v5.0","tcms-api-5.0","v4.2","tcms-api-4.2","v4.1.4","v4.1.3","v4.1.2","v4.1.1","v4.1.0","v4.0.0","tcms-api-4.0.0","v3.50","tcms-api-1.5.1","v3.49","tcms-api-1.5.0","tcms-api-1.4.0","v3.48","v3.44","v3.41","v3.39","v3.38","v3.37","v3.33","v3.32","v3.30","v3.28","v3.26","v3.23","v3.22","v3.21.2","v3.21.1","v3.8.18.21","v3.8.18"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54724.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}