CVE-2026-54218 Details
Description
Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using only obfuscation. Any user with access to the server’s file system, or who can otherwise extract files from the server (see vulnerability “Random File Read”), can potentially obtain affected users’ passwords. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
A vulnerability exists in Tobit Laboratories TeamDavid's Webbox, allowing for the extraction of passwords for locally created users. Passwords are stored in various files using only obfuscation, not encryption. Any user with access to the server's file system or who can extract files from the server can potentially retrieve these passwords. This vulnerability affects TeamDavid through Rollout 524.
Users are advised to update to the latest version of TeamDavid, as the current version may still have unresolved vulnerabilities. Additionally, avoid exposing the TeamDavid web server directly to the internet. Instead, place it behind a VPN or a reverse proxy that filters requests and blocks access to non-essential endpoints. Rotate credentials, as the reversible password storage could have allowed for password leakage.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 7, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/ | CISA-ADP | BundleRemedyTechnical Analysis |
| https://chayns.net/77892-10814/tapp/763210?postId=11454 | [email protected] | |
| https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/ | [email protected] | BundleRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Tobit Laboratories AG TeamDavid | >= 524, < 525 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 7, 2026 | CVE Modified | [email protected] |
| Sep 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | [email protected] |
Volerion