CVE-2026-49292
Last modified
CVE-2026-49292 is a none-severity vulnerability. Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migrate.
Description
Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migrate. The migration command is reentrant, so repeated access reports that no migrations are available and does not cause data loss, alter application state, reveal confidential information, or produce a documented availability impact. This issue is fixed in version 16.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| kiwitcms | Kiwi | < 16.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-49292?
How severe is CVE-2026-49292?
How do I fix CVE-2026-49292?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-49287Statamic is a Laravel and Git powered content management sys…7.4
- CVE-2026-49288Statamic is a Laravel and Git powered content management sys…4.3
- CVE-2026-49289The SimpleSAMLphp SAML2 library is a PHP library for SAML2 r…7.5
- CVE-2026-4929Simple Hierarchical Select (SHS) for Drupal 7 contains cross…5.4
- CVE-2026-49290Slopsmith is a self-contained web application for browsing, …7.6
- CVE-2026-49291mcp-memory-service is a semantic memory layer for AI applica…8.1
- CVE-2026-49293js-toml is a TOML parser for JavaScript, fully compliant wit…7.5
- CVE-2026-49294Valhalla is an open source routing engine and accompanying l…6.1
- CVE-2026-49295libde265 is an open source implementation of the h.265 video…7.1
- CVE-2026-49296Before apache-airflow 3.3.0, a user authorized to read one D…6.5
- CVE-2026-49297Apache Airflow's Google provider operators `GCSToSFTPOperato…8.1
- CVE-2026-49298A bug in Apache Airflow's KubernetesExecutor caused JWT toke…8.8
Are you affected by CVE-2026-49292?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
