CVE-2026-54203 Details
Description
Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with memory. By repeatedly requesting this endpoint, an attacker can access sensitive information, including user passwords. Exploitation does not require authentication. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
A memory leak vulnerability has been identified in Tobit Laboratories TeamDavid's Webbox, prior to Rollout 524. This vulnerability allows unauthorized actors to read sensitive information, including user passwords. The issue arises when the URL '/.well-known/mta-sts.' is accessed. The application responds by leaking residual memory from previous requests. By repeatedly requesting this endpoint, an attacker can extract up to 4 kilobytes of uninitialized heap memory, which may contain sensitive data such as 'access.ini' files with decrypted passwords. Exploitation does not require authentication.
Users are advised to update to the latest version of TeamDavid, as the vulnerabilities appear to be fixed in this release. Rotate credentials, as the reversible password storage means any prior file-system exposure may have leaked usable passwords.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2026CISA-ADP
Assessed Aug 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://chayns.net/77892-10814/tapp/763210?postId=11454 | [email protected] | |
| https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/ | [email protected] | BundleRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Tobit Laboratories AG TeamDavid | <= 524 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 7, 2026 | CVE Modified | [email protected] |
| Aug 10, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |
Volerion