{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-12071","assignerOrgId":"455daabc-a392-441d-aa46-37d35189897c","state":"PUBLISHED","assignerShortName":"NCSC.ch","dateReserved":"2026-06-12T09:32:52.061Z","datePublished":"2026-08-07T09:40:52.596Z","dateUpdated":"2026-09-07T12:40:34.507Z"},"containers":{"cna":{"providerMetadata":{"orgId":"455daabc-a392-441d-aa46-37d35189897c","shortName":"NCSC.ch","dateUpdated":"2026-09-07T12:40:34.507Z"},"title":"TeamDavid: Header Injection leading to Open Redirect via URL-encoded characters","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-601","description":"CWE-601 URL redirection to untrusted site ('open redirect')","type":"CWE"}]}],"affected":[{"vendor":"Tobit Laboratories AG","product":"TeamDavid","modules":["Webbox"],"versions":[{"status":"affected","version":"0","lessThan":"Rollout 528","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"The Webbox of TeamDavid by Tobit Laboratories AG constructs redirect URLs using user-supplied input, \nwhich is appended to the redirect target in a 302 HTTP response. By \nusing URL-encoded characters such as “%2e” (representing a dot), an \nattacker can manipulate the portion of the URL following the top-level \ndomain (TLD). If a similar, registerable TLD exists (for example, if \n“.com” is the application’s domain, and “.company” is available for \nregistration), an attacker can craft a URL to redirect users to a \nmalicious “.company” domain. By using URL-encoded line feeds, it becomes\n possible to insert arbitrary response headers in the server's HTTP \nresponse.\n\n\n\n\n\n\nThis issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.","supportingMedia":[{"type":"text/html","base64":false,"value":"<div>The Webbox of TeamDavid by&nbsp;Tobit Laboratories AG&nbsp;constructs redirect URLs using user-supplied input, \nwhich is appended to the redirect target in a 302 HTTP response. By \nusing URL-encoded characters such as “%2e” (representing a dot), an \nattacker can manipulate the portion of the URL following the top-level \ndomain (TLD). If a similar, registerable TLD exists (for example, if \n“.com” is the application’s domain, and “.company” is available for \nregistration), an attacker can craft a URL to redirect users to a \nmalicious “.company” domain. By using URL-encoded line feeds, it becomes\n possible to insert arbitrary response headers in the server's HTTP \nresponse.</div><p><br></p><div><div><span>This issue affects TeamDavid before Rollout 528.</span></div><div><span>Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.</span></div><br></div><p><br></p>"}]}],"references":[{"url":"https://chayns.net/77892-10814/tapp/763210?postId=11454","tags":["release-notes"]},{"url":"https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/","tags":["third-party-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE","vulnConfidentialityImpact":"LOW","subConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW","subIntegrityImpact":"LOW","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N"}}],"credits":[{"lang":"en","value":"Dario Weiss of InfoGuard Labs","type":"finder"},{"lang":"en","value":"Olivier Becker of InfoGuard Labs","type":"finder"},{"lang":"en","value":"Lucas Dodgson of InfoGuard Labs","type":"finder"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.2"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-10T11:19:50.374307Z","id":"CVE-2026-12071","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-10T11:21:46.019Z"}}]}}