{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-54212","assignerOrgId":"455daabc-a392-441d-aa46-37d35189897c","state":"PUBLISHED","assignerShortName":"NCSC.ch","dateReserved":"2026-06-12T09:32:46.514Z","datePublished":"2026-08-07T09:47:12.542Z","dateUpdated":"2026-09-07T12:58:58.837Z"},"containers":{"cna":{"providerMetadata":{"orgId":"455daabc-a392-441d-aa46-37d35189897c","shortName":"NCSC.ch","dateUpdated":"2026-09-07T12:58:58.837Z"},"title":"TeamDavid: Buffer Overflow in JSON-parsing","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-787","description":"CWE-787 Out-of-bounds write","type":"CWE"}]}],"affected":[{"vendor":"Tobit Laboratories AG","product":"TeamDavid","modules":["Webbox"],"versions":[{"status":"affected","version":"0","lessThan":"Rollout 528","versionType":"custom"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a \nbuffer overflow condition. By submitting a specially crafted JSON body, \nsuch as one that is at least 8 characters long and begins with a number,\n an unauthenticated attacker can cause the server to crash, resulting in\n denial of service. Depending on the stack state or if a stack canary \ncan be disclosed through another vulnerability, this buffer overflow \ncould potentially lead to remote code execution and full compromise of \nthe server. This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.","supportingMedia":[{"type":"text/html","base64":false,"value":"Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a \nbuffer overflow condition. By submitting a specially crafted JSON body, \nsuch as one that is at least 8 characters long and begins with a number,\n an unauthenticated attacker can cause the server to crash, resulting in\n denial of service. Depending on the stack state or if a stack canary \ncan be disclosed through another vulnerability, this buffer overflow \ncould potentially lead to remote code execution and full compromise of \nthe server.&nbsp;<div><div><span>This issue affects TeamDavid before Rollout 528.</span></div><div><span>Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.</span></div></div>"}]}],"references":[{"url":"https://chayns.net/77892-10814/tapp/763210?postId=11454","tags":["release-notes"]},{"url":"https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/","tags":["third-party-advisory"]}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"HIGH","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"CRITICAL","baseScore":9.5,"vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}}],"credits":[{"lang":"en","value":"Lucas Dodgson of InfoGuard Labs","type":"finder"}],"source":{"discovery":"EXTERNAL"},"x_generator":{"engine":"Vulnogram 1.0.2"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-07T14:38:05.213025Z","id":"CVE-2026-54212","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-07T14:38:27.060Z"}}]}}