{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-54201","assignerOrgId":"455daabc-a392-441d-aa46-37d35189897c","state":"PUBLISHED","assignerShortName":"NCSC.ch","dateReserved":"2026-06-12T09:32:44.531Z","datePublished":"2026-08-07T09:43:18.647Z","dateUpdated":"2026-09-07T12:45:29.829Z"},"containers":{"cna":{"providerMetadata":{"orgId":"455daabc-a392-441d-aa46-37d35189897c","shortName":"NCSC.ch","dateUpdated":"2026-09-07T12:45:29.829Z"},"title":"TeamDavid: Missing Authorization","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-862","description":"CWE-862 Missing Authorization","type":"CWE"}]}],"affected":[{"vendor":"Tobit Laboratories AG","product":"TeamDavid","modules":["Webbox"],"versions":[{"status":"affected","version":"0","lessThan":"Rollout 528","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Tobit Laboratories AG TeamDavid's Webbox  does not enforce authentication or authorization checks\n when serving these log files. As a result, attackers can obtain \nsensitive error information or internal application details, potentially\n aiding in further attacks. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.","supportingMedia":[{"type":"text/html","base64":false,"value":"Tobit Laboratories AG TeamDavid's Webbox  does not enforce authentication or authorization checks\n when serving these log files. As a result, attackers can obtain \nsensitive error information or internal application details, potentially\n aiding in further attacks.&nbsp;<div><div><span>This issue affects TeamDavid before Rollout 528.</span></div><div><span>Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.</span></div></div>"}]}],"references":[{"url":"https://chayns.net/77892-10814/tapp/763210?postId=11454","tags":["release-notes"]},{"url":"https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/","tags":["third-party-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"LOW","subConfidentialityImpact":"LOW","vulnIntegrityImpact":"NONE","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":6.9,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N"}}],"credits":[{"lang":"en","value":"Dario Weiss of InfoGuard Labs","type":"finder"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.2"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-10T11:30:50.391724Z","id":"CVE-2026-54201","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-10T11:33:56.141Z"}}]}}