{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-54215", "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c", "state": "PUBLISHED", "assignerShortName": "NCSC.ch", "dateReserved": "2026-06-12T09:32:46.514Z", "datePublished": "2026-08-07T09:48:16.069Z", "dateUpdated": "2026-09-07T13:01:19.082Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "455daabc-a392-441d-aa46-37d35189897c", "shortName": "NCSC.ch", "dateUpdated": "2026-09-07T13:01:19.082Z" }, "title": "TeamDavid: Open Redirect via the 'replyUrl' parameter", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-601", "description": "CWE-601 URL redirection to untrusted site ('open redirect')", "type": "CWE" } ] } ], "affected": [ { "vendor": "Tobit Laboratories AG", "product": "TeamDavid", "modules": [ "Webbox" ], "versions": [ { "status": "affected", "version": "0", "lessThan": "Rollout 528", "versionType": "custom" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the \n“replyUrl” parameter. An attacker can exploit this vulnerability to \ncraft a URL within the application that, when visited, redirects the \nuser’s browser to an arbitrary third-party site. This can be abused for \nphishing attacks, where users receive a trusted domain link but are \nredirected to a phishing website. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the \n“replyUrl” parameter. An attacker can exploit this vulnerability to \ncraft a URL within the application that, when visited, redirects the \nuser’s browser to an arbitrary third-party site. This can be abused for \nphishing attacks, where users receive a trusted domain link but are \nredirected to a phishing website. 
This issue affects TeamDavid before Rollout 528.
Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
" } ] } ], "references": [ { "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454", "tags": [ "release-notes" ] }, { "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/", "tags": [ "third-party-advisory" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV4_0": { "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "PASSIVE", "vulnConfidentialityImpact": "LOW", "subConfidentialityImpact": "LOW", "vulnIntegrityImpact": "LOW", "subIntegrityImpact": "LOW", "vulnAvailabilityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED", "version": "4.0", "baseSeverity": "MEDIUM", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N" } } ], "credits": [ { "lang": "en", "value": "Dario Weiss of InfoGuard Labs", "type": "finder" } ], "source": { "discovery": "EXTERNAL" }, "x_generator": { "engine": "Vulnogram 1.0.2" } }, "adp": [ { "references": [ { "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/", "tags": [ "exploit" ] } ], "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-08-07T11:24:50.530508Z", "id": "CVE-2026-54215", "options": [ { "Exploitation": "poc" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-07T11:25:12.256Z" } } ] } }