Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v8rp-6xcv-fwgh | Kiwi TCMS's /init-db/ page renders and responds to requests after first use |
Thu, 17 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migrate. The migration command is reentrant, so repeated access reports that no migrations are available and does not cause data loss, alter application state, reveal confidential information, or produce a documented availability impact. This issue is fixed in version 16.0. | |
| Title | Kiwi TCMS: The /init-db/ page renders and responds to requests after first use | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-17T19:11:15.766Z
Reserved: 2026-05-28T20:07:58.862Z
Link: CVE-2026-49292
Updated: 2026-09-17T19:11:10.589Z
Status : Received
Published: 2026-09-17T19:16:48.960
Modified: 2026-09-17T20:16:50.007
Link: CVE-2026-49292
No data.
OpenCVE Enrichment
No data.
-
CWE-862
Missing Authorization
Github GHSA