{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-54200", "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c", "state": "PUBLISHED", "assignerShortName": "NCSC.ch", "dateReserved": "2026-06-12T09:32:44.531Z", "datePublished": "2026-08-07T09:41:49.863Z", "dateUpdated": "2026-09-07T12:44:25.997Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "455daabc-a392-441d-aa46-37d35189897c", "shortName": "NCSC.ch", "dateUpdated": "2026-09-07T12:44:25.997Z" }, "title": "TeamDavid: Local File Inclusion via the form field 'scjob'", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-73", "description": "CWE-73 External Control of File Name or Path", "type": "CWE" } ] } ], "affected": [ { "vendor": "Tobit Laboratories AG", "product": "TeamDavid", "modules": [ "Webbox" ], "versions": [ { "status": "affected", "version": "0", "lessThan": "Rollout 528", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in\n the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message, \nwhich can then be downloaded by an authenticated user. A filter is in \nplace that restricts access to the David con-fig folder and the user \nfolder. However, this filter can be bypassed by specifying an alternate \ndata stream, allowing the download of sensitive files such as other \nusers' access files containing their passwords or the server's private \nkey. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in\n the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message, \nwhich can then be downloaded by an authenticated user. A filter is in \nplace that restricts access to the David con-fig folder and the user \nfolder. However, this filter can be bypassed by specifying an alternate \ndata stream, allowing the download of sensitive files such as other \nusers' access files containing their passwords or the server's private \nkey. 
This issue affects TeamDavid before Rollout 528.
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
" } ] } ], "references": [ { "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454", "tags": [ "release-notes" ] }, { "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/", "tags": [ "third-party-advisory" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "HIGH", "subConfidentialityImpact": "HIGH", "vulnIntegrityImpact": "LOW", "subIntegrityImpact": "NONE", "vulnAvailabilityImpact": "LOW", "subAvailabilityImpact": "LOW", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "HIGH", "baseScore": 8.4, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:N/SA:L" } } ], "credits": [ { "lang": "en", "value": "Dario Weiss of InfoGuard Labs", "type": "finder" } ], "source": { "discovery": "UNKNOWN" }, "x_generator": { "engine": "Vulnogram 1.0.2" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-08-10T11:27:41.186723Z", "id": "CVE-2026-54200", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-10T11:30:06.099Z" } } ] } }