{"api_version":"1","generated_at":"2026-08-14T18:45:02+00:00","cve":"CVE-2026-54209","urls":{"html":"https://cve.report/CVE-2026-54209","api":"https://cve.report/api/cve/CVE-2026-54209.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-54209","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-54209"},"summary":{"title":"TeamDavid: Buffer Overflow in 'editini' function","description":"Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by \nincluding the string \"(editini)\" in the file path, writing the new \npassword to the specified \"Archive.ini\" file. However, the application \ndoes not verify that the provided path actually refers to an \n\"Archive.ini\" file. If an attacker specifies a different file with \nexcessive size, a buffer overflow occurs. This vulnerability allows an \nunauthenticated attacker to crash the server, resulting in denial of \nservice. This issue affects TeamDavid through Rollout 524.","state":"PUBLISHED","assigner":"NCSC.ch","published_at":"2026-08-07 10:16:57","updated_at":"2026-08-07 15:17:01"},"problem_types":["CWE-125","CWE-125 CWE-125 Out-of-bounds read"],"metrics":[{"version":"4.0","source":"vulnerability@ncsc.ch","type":"Secondary","score":"8.9","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.9,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"8.9","severity":"HIGH","vector":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.9,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://david.tobit.software/releasenotes","name":"https://david.tobit.software/releasenotes","refsource":"vulnerability@ncsc.ch","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/","name":"https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/","refsource":"vulnerability@ncsc.ch","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-54209","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54209","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Tobit Laboratories AG","product":"TeamDavid","version":"affected Rollout 524 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Dario Weiss of InfoGuard Labs","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"54209","cve":"CVE-2026-54209","epss":"0.002870000","percentile":"0.208890000","score_date":"2026-08-10","updated_at":"2026-08-11 00:09:46"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-54209","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-08-07T14:41:05.833002Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-07T14:41:12.866Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","modules":["Webbox"],"product":"TeamDavid","vendor":"Tobit Laboratories AG","versions":[{"lessThanOrEqual":"Rollout 524","status":"affected","version":"0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Dario Weiss of InfoGuard Labs"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by \nincluding the string \"(editini)\" in the file path, writing the new \npassword to the specified \"Archive.ini\" file. However, the application \ndoes not verify that the provided path actually refers to an \n\"Archive.ini\" file. If an attacker specifies a different file with \nexcessive size, a buffer overflow occurs. This vulnerability allows an \nunauthenticated attacker to crash the server, resulting in denial of \nservice.&nbsp;This issue affects TeamDavid through Rollout 524."}],"value":"Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by \nincluding the string \"(editini)\" in the file path, writing the new \npassword to the specified \"Archive.ini\" file. However, the application \ndoes not verify that the provided path actually refers to an \n\"Archive.ini\" file. If an attacker specifies a different file with \nexcessive size, a buffer overflow occurs. This vulnerability allows an \nunauthenticated attacker to crash the server, resulting in denial of \nservice. This issue affects TeamDavid through Rollout 524."}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.9,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-125","description":"CWE-125 Out-of-bounds read","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-07T09:45:53.568Z","orgId":"455daabc-a392-441d-aa46-37d35189897c","shortName":"NCSC.ch"},"references":[{"tags":["release-notes"],"url":"https://david.tobit.software/releasenotes"},{"tags":["third-party-advisory"],"url":"https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"}],"source":{"discovery":"EXTERNAL"},"title":"TeamDavid: Buffer Overflow in 'editini' function","x_generator":{"engine":"Vulnogram 1.0.2"}}},"cveMetadata":{"assignerOrgId":"455daabc-a392-441d-aa46-37d35189897c","assignerShortName":"NCSC.ch","cveId":"CVE-2026-54209","datePublished":"2026-08-07T09:45:53.568Z","dateReserved":"2026-06-12T09:32:46.514Z","dateUpdated":"2026-08-07T14:41:12.866Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-07 10:16:57","lastModifiedDate":"2026-08-07 15:17:01","problem_types":["CWE-125","CWE-125 CWE-125 Out-of-bounds read"],"metrics":{"cvssMetricV40":[{"source":"vulnerability@ncsc.ch","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":8.9,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"HIGH","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-07T14:41:05.833002Z","id":"CVE-2026-54209","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"54209","Ordinal":"1","Title":"TeamDavid: Buffer Overflow in 'editini' function","CVE":"CVE-2026-54209","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"54209","Ordinal":"1","NoteData":"Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by \nincluding the string \"(editini)\" in the file path, writing the new \npassword to the specified \"Archive.ini\" file. However, the application \ndoes not verify that the provided path actually refers to an \n\"Archive.ini\" file. If an attacker specifies a different file with \nexcessive size, a buffer overflow occurs. This vulnerability allows an \nunauthenticated attacker to crash the server, resulting in denial of \nservice. This issue affects TeamDavid through Rollout 524.","Type":"Description","Title":"TeamDavid: Buffer Overflow in 'editini' function"}]}}}