Search

Find a vulnerability

Search criteria

    214 vulnerabilities

    CVE-2026-104811 (GCVE-0-2026-104811)

    Vulnerability from cvelistv5 – Published: 2026-10-05 08:34 – Updated: 2026-10-05 12:38
    VLAI
    Title
    Mitel MiVoice Office 400 Music on Hold WAV File Upload Code Execution
    Summary
    DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability. The specific flaw exists within the Configuration → Services → Music on Hold functionality of the web portal listening on TCP port 443. The application is intended to allow users to upload WAV audio files but fails to properly validate the uploaded file type. An attacker can exploit this behavior to upload a malicious shared object (.so) instead of a WAV file. When the uploaded file is subsequently processed by the affected component, attacker-controlled code is loaded and executed in the context of the affected process. This can result in remote code execution and potentially full compromise of the underlying Linux system.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 12:37 UTC
    CWE
    • CWE-434 - — Unrestricted Upload of File with Dangerous Type
    • CWE-20 - — Improper Input Validation
    • CWE-94 - — Improper Control of Generation of Code ('Code Injection')
    • CWE-829 - — Inclusion of Functionality from Untrusted Control Sphere
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104811",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T12:37:39.945496Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T12:38:56.148Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Mitel MiVoice Office 400",
              "vendor": "Mitel",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.0.96.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Brian Mariani from DigitalCanion SA"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eDigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability.\u003c/p\u003e\n\u003cp\u003eThe specific flaw exists within the Configuration \u2192 Services \u2192 Music on Hold functionality of the web portal listening on TCP port 443. The application is intended to allow users to upload WAV audio files but fails to properly validate the uploaded file type. An attacker can exploit this behavior to upload a malicious shared object (\u003ccode\u003e.so\u003c/code\u003e) instead of a WAV file. When the uploaded file is subsequently processed by the affected component, attacker-controlled code is loaded and executed in the context of the affected process. This can result in remote code execution and potentially full compromise of the underlying Linux system.\u003c/p\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\n\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e"
                }
              ],
              "value": "DigitalCanion SA has discovered a vulnerability that allows remote attackers to execute arbitrary code on affected installations of the product. Authentication may be required to exploit this vulnerability.\n\n\n\n\nThe specific flaw exists within the Configuration \u2192 Services \u2192 Music on Hold functionality of the web portal listening on TCP port 443. The application is intended to allow users to upload WAV audio files but fails to properly validate the uploaded file type. An attacker can exploit this behavior to upload a malicious shared object (.so) instead of a WAV file. When the uploaded file is subsequently processed by the affected component, attacker-controlled code is loaded and executed in the context of the affected process. This can result in remote code execution and potentially full compromise of the underlying Linux system."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-650",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-650 \u2014 Upload a Web Service with Malicious Content"
                }
              ]
            },
            {
              "capecId": "CAPEC-242",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-242 \u2014 Code Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/AU:Y/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434 \u2014 Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 \u2014 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-94",
                  "description": "CWE-94 \u2014 Improper Control of Generation of Code (\u0027Code Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-829",
                  "description": "CWE-829 \u2014 Inclusion of Functionality from Untrusted Control Sphere",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T08:34:38.102Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://digitalcanion.com/en/security-research/#vendor=mitel\u0026status=cna"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Mitel MiVoice Office 400 Music on Hold WAV File Upload Code Execution",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-104811",
        "datePublished": "2026-10-05T08:34:38.102Z",
        "dateReserved": "2026-10-02T13:47:47.693Z",
        "dateUpdated": "2026-10-05T12:38:56.148Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104810 (GCVE-0-2026-104810)

    Vulnerability from cvelistv5 – Published: 2026-10-05 08:33 – Updated: 2026-10-05 12:45
    VLAI
    Title
    Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability
    Summary
    This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability. The specific flaw exists within the web portal listening on TCP port 443, under Maintenance → File Management → File Browser, which is affected by a directory traversal vulnerability. By exploiting this vulnerability, an authenticated attacker can access and delete files outside of the intended directory, including files belonging to the Mitel application and the underlying Linux system. Deleting critical system or application files can result in a denial-of-service condition affecting the underlying system.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 12:45 UTC
    CWE
    • CWE-31 - Path traversal: 'dir\..\..\filename'
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104810",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T12:45:07.682452Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T12:45:28.305Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Mitel MiVoice Office 400",
              "vendor": "Mitel",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.0.96.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Brian Mariani from DigitalCanion SA"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eThis vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability.\u003c/p\u003e\n\u003cp\u003eThe specific flaw exists within the web portal listening on TCP port 443, under Maintenance \u2192 File Management \u2192 File Browser, which is affected by a directory traversal vulnerability. By exploiting this vulnerability, an authenticated attacker can access and delete files outside of the intended directory, including files belonging to the Mitel application and the underlying Linux system. Deleting critical system or application files can result in a denial-of-service condition affecting the underlying system.\u003c/p\u003e\n\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\n\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e"
                }
              ],
              "value": "This vulnerability allows remote attackers to delete sensitive files on vulnerable installations of Mitel MiVoice Office 400. Authentication is required to exploit this vulnerability.\n\n\n\n\nThe specific flaw exists within the web portal listening on TCP port 443, under Maintenance \u2192 File Management \u2192 File Browser, which is affected by a directory traversal vulnerability. By exploiting this vulnerability, an authenticated attacker can access and delete files outside of the intended directory, including files belonging to the Mitel application and the underlying Linux system. Deleting critical system or application files can result in a denial-of-service condition affecting the underlying system."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/AU:Y/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-31",
                  "description": "CWE-31 Path traversal: \u0027dir\\..\\..\\filename\u0027",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T08:33:36.306Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://digitalcanion.com/en/security-research/#vendor=mitel\u0026status=cna"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-104810",
        "datePublished": "2026-10-05T08:33:36.306Z",
        "dateReserved": "2026-10-02T13:47:47.693Z",
        "dateUpdated": "2026-10-05T12:45:28.305Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104809 (GCVE-0-2026-104809)

    Vulnerability from cvelistv5 – Published: 2026-10-05 08:32 – Updated: 2026-10-05 12:55
    VLAI
    Title
    Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution
    Summary
    DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file’s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 12:53 UTC
    CWE
    • CWE-73 - External control of file name or path
    • CWE-494 - Download of code without integrity check
    • CWE-829 - Inclusion of functionality from untrusted control sphere
    • CWE-426 - — Untrusted Search Path
    • CWE-427 - — Uncontrolled Search Path Element
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104809",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T12:53:58.881891Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T12:55:24.978Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Mitel MiVoice Office 400",
              "vendor": "Mitel",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.0.96.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Brian Mariani from DigitalCanion SA"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eDigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled \u003ccode\u003e.so\u003c/code\u003e file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file\u2019s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003e\u003c/div\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\n\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003c/div\u003e\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e"
                }
              ],
              "value": "DigitalCanion has discovered a vulnerability that allows an attacker to cause the system to load an attacker-controlled .so file instead of the expected legitimate module. The loading mechanism relies on a predictable module name without adequately verifying the file\u2019s origin or integrity. A malicious shared object using the expected name can therefore be loaded by a privileged process. The module code then executes within the context and privileges of that process. This results in arbitrary code execution and full compromise of the Mitel Linux virtual machine."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-471",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-471 \u2014 Search Order Hijacking"
                }
              ]
            },
            {
              "capecId": "CAPEC-159",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-159 \u2014 Redirect Access to Libraries"
                }
              ]
            },
            {
              "capecId": "CAPEC-642",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-642 \u2014 Replace Binaries"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/AU:Y/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73 External control of file name or path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-494",
                  "description": "CWE-494 Download of code without integrity check",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-829",
                  "description": "CWE-829 Inclusion of functionality from untrusted control sphere",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-426",
                  "description": "CWE-426 \u2014 Untrusted Search Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-427",
                  "description": "CWE-427 \u2014 Uncontrolled Search Path Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T08:32:14.233Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://digitalcanion.com/en/security-research/#vendor=mitel\u0026status=cna"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Mitel MiVoice Office 400 Shared Object Hijacking Leading to Arbitrary Code Execution",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-104809",
        "datePublished": "2026-10-05T08:32:14.233Z",
        "dateReserved": "2026-10-02T13:47:47.693Z",
        "dateUpdated": "2026-10-05T12:55:24.978Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104808 (GCVE-0-2026-104808)

    Vulnerability from cvelistv5 – Published: 2026-10-05 08:30 – Updated: 2026-10-05 13:08
    VLAI
    Title
    Mitel MiVoice Office 400 stored Cross-Site Scripting
    Summary
    DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content, resulting in a denial-of-service condition within the web application. The specific flaw exists within the web portal listening on TCP port 443, under Configuration → Users → Users List. The vulnerability occurs in the “Microsoft Exchange mailbox” field, which fails to properly validate or sanitize user-supplied input before storing and rendering it. By injecting malicious JavaScript into this field, an attacker can cause the payload to execute whenever the affected user properties are accessed. This can prevent access to the affected user properties and result in a denial-of-service condition within the application's user-management functionality.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 13:04 UTC
    CWE
    • CWE-79 - Improper neutralization of input during web page generation ('cross-site scripting')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104808",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T13:04:14.743968Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T13:08:09.637Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Mitel MiVoice Office 400",
              "vendor": "Mitel",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.0.96.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Brian Mariani from DigitalCanion SA"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eDigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content, resulting in a denial-of-service condition within the web application.\u003c/p\u003e\n\u003cp\u003eThe specific flaw exists within the web portal listening on TCP port 443, under \u003cstrong\u003eConfiguration \u2192 Users \u2192 Users List\u003c/strong\u003e. The vulnerability occurs in the \u003cstrong\u003e\u201cMicrosoft Exchange mailbox\u201d\u003c/strong\u003e field, which fails to properly validate or sanitize user-supplied input before storing and rendering it.\u003c/p\u003e\n\u003cp\u003eBy injecting malicious JavaScript into this field, an attacker can cause the payload to execute whenever the affected user properties are accessed. This can prevent access to the affected user properties and result in a denial-of-service condition within the application\u0027s user-management functionality.\u003c/p\u003e"
                }
              ],
              "value": "DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content, resulting in a denial-of-service condition within the web application.\n\n\n\n\nThe specific flaw exists within the web portal listening on TCP port 443, under Configuration \u2192 Users \u2192 Users List. The vulnerability occurs in the \u201cMicrosoft Exchange mailbox\u201d field, which fails to properly validate or sanitize user-supplied input before storing and rendering it.\n\n\n\n\nBy injecting malicious JavaScript into this field, an attacker can cause the payload to execute whenever the affected user properties are accessed. This can prevent access to the affected user properties and result in a denial-of-service condition within the application\u0027s user-management functionality."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-63",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-63 Cross-Site Scripting (XSS)"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "AUTOMATIC",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 1.9,
                "baseSeverity": "LOW",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "valueDensity": "DIFFUSE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/AU:Y/R:A/V:D/RE:L/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "LOW"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T08:30:54.909Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://digitalcanion.com/en/security-research/#vendor=mitel\u0026status=cna"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Mitel MiVoice Office 400 stored Cross-Site Scripting",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-104808",
        "datePublished": "2026-10-05T08:30:54.909Z",
        "dateReserved": "2026-10-02T13:47:47.692Z",
        "dateUpdated": "2026-10-05T13:08:09.637Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104807 (GCVE-0-2026-104807)

    Vulnerability from cvelistv5 – Published: 2026-10-05 08:28 – Updated: 2026-10-05 13:11
    VLAI
    Title
    Mitel MiVoice Office 400 stored Cross-Site Scripting
    Summary
    DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application. The specific flaw exists within the web portal listening on TCP port 443, under Configuration → Domains, specifically in the “Description” field. The application fails to properly validate or sanitize user-supplied input before storing and subsequently rendering the field. By injecting malicious JavaScript into the Description field, an attacker can modify the content and behavior of the affected page when it is viewed by other users. This could allow an attacker to alter the page's appearance, display attacker-controlled content, or construct convincing phishing scenarios within the application's trusted web context.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 13:11 UTC
    CWE
    • CWE-79 - Improper neutralization of input during web page generation ('cross-site scripting')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104807",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T13:11:15.358627Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T13:11:29.180Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Mitel MiVoice Office 400",
              "vendor": "Mitel",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.0.96.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Brian Mariani from DigitalCanion SA"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eDigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application.\u003c/p\u003e\n\u003cp\u003eThe specific flaw exists within the web portal listening on TCP port 443, under \u003cstrong\u003eConfiguration \u2192 Domains\u003c/strong\u003e, specifically in the \u003cstrong\u003e\u201cDescription\u201d\u003c/strong\u003e field. The application fails to properly validate or sanitize user-supplied input before storing and subsequently rendering the field.\u003c/p\u003e\n\u003cp\u003eBy injecting malicious JavaScript into the \u003cstrong\u003eDescription\u003c/strong\u003e field, an attacker can modify the content and behavior of the affected page when it is viewed by other users. This could allow an attacker to alter the page\u0027s appearance, display attacker-controlled content, or construct convincing phishing scenarios within the application\u0027s trusted web context.\u003c/p\u003e\n\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "DigitalCanion has discovered a stored Cross-Site Scripting (XSS) vulnerability that allows an authenticated malicious user to inject persistent JavaScript or HTML content into the web application.\n\n\n\n\nThe specific flaw exists within the web portal listening on TCP port 443, under Configuration \u2192 Domains, specifically in the \u201cDescription\u201d field. The application fails to properly validate or sanitize user-supplied input before storing and subsequently rendering the field.\n\n\n\n\nBy injecting malicious JavaScript into the Description field, an attacker can modify the content and behavior of the affected page when it is viewed by other users. This could allow an attacker to alter the page\u0027s appearance, display attacker-controlled content, or construct convincing phishing scenarios within the application\u0027s trusted web context."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-63",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-63 Cross-Site Scripting (XSS)"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "AUTOMATIC",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 1.9,
                "baseSeverity": "LOW",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "valueDensity": "DIFFUSE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/AU:Y/R:A/V:D/RE:L/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "LOW"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T08:28:58.184Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://digitalcanion.com/en/security-research/#vendor=mitel\u0026status=cna"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Mitel MiVoice Office 400 stored Cross-Site Scripting",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-104807",
        "datePublished": "2026-10-05T08:28:58.184Z",
        "dateReserved": "2026-10-02T13:47:47.692Z",
        "dateUpdated": "2026-10-05T13:11:29.180Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104806 (GCVE-0-2026-104806)

    Vulnerability from cvelistv5 – Published: 2026-10-05 08:24 – Updated: 2026-10-05 13:52
    VLAI
    Title
    Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure
    Summary
    DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory. The specific flaw exists within the Maintenance → System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate user-supplied file paths, allowing an attacker to manipulate the requested path and traverse the underlying directory structure. By exploiting this vulnerability, an attacker can access and download files located outside the intended system logs directory, including potentially sensitive system and application files.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 13:50 UTC
    CWE
    • CWE-31 - Path traversal: 'dir\..\..\filename'
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104806",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T13:50:17.307733Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T13:52:56.571Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Mitel MiVoice Office 400",
              "vendor": "Mitel",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.0.96.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Brian Mariani from DigitalCanion SA"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eDigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory.\u003c/p\u003e\n\u003cp\u003eThe specific flaw exists within the Maintenance \u2192 System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate user-supplied file paths, allowing an attacker to manipulate the requested path and traverse the underlying directory structure.\u003c/p\u003e\n\u003cp\u003eBy exploiting this vulnerability, an attacker can access and download files located outside the intended system logs directory, including potentially sensitive system and application files.\u003c/p\u003e\n\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "DigitalCanion has discovered a path traversal vulnerability that allows an attacker to access files outside of the intended directory.\n\n\n\n\nThe specific flaw exists within the Maintenance \u2192 System Logs functionality of the web management portal listening on TCP port 443. The application fails to properly validate user-supplied file paths, allowing an attacker to manipulate the requested path and traverse the underlying directory structure.\n\n\n\n\nBy exploiting this vulnerability, an attacker can access and download files located outside the intended system logs directory, including potentially sensitive system and application files."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "AUTOMATIC",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "DIFFUSE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/AU:Y/R:A/V:D/RE:L/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "LOW"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-31",
                  "description": "CWE-31 Path traversal: \u0027dir\\..\\..\\filename\u0027",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T08:24:22.042Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://digitalcanion.com/en/security-research/#vendor=mitel\u0026status=cna"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-104806",
        "datePublished": "2026-10-05T08:24:22.042Z",
        "dateReserved": "2026-10-02T13:47:45.135Z",
        "dateUpdated": "2026-10-05T13:52:56.571Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104805 (GCVE-0-2026-104805)

    Vulnerability from cvelistv5 – Published: 2026-10-05 08:22 – Updated: 2026-10-05 12:57
    VLAI
    Title
    Mitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to Root Code Execution
    Summary
    DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration. The specific flaw exists within the backup restoration mechanism, which fails to properly validate the paths, file types, integrity, and authenticity of files contained within a restored TGZ archive. The application does not perform file-signature verification before extracting the archive, allowing a specially crafted backup to contain attacker-controlled files. An attacker with access to the backup SFTP or other configured repository can therefore provide a malicious TGZ archive that, when restored by the system, may place arbitrary files on the underlying Linux system. Depending on the location and permissions of the extracted files, this behavior can potentially be leveraged to achieve arbitrary code execution with root privileges and compromise the underlying virtual machine. The absence of enforced backup passwords further reduces the protection provided by the backup mechanism and may facilitate unauthorized access to the repository.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 12:57 UTC
    CWE
    • CWE-22 - — Path Traversal
    • CWE-73 - — External Control of File Name or Path
    • CWE-494 - — Download of Code Without Integrity Check
    • CWE-345 - — Insufficient Verification of Data Authenticity
    • CWE-434 - — Unrestricted Upload of File with Dangerous Type
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104805",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T12:57:00.814880Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T12:57:11.157Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Mitel MiVoice Office 400",
              "vendor": "Mitel",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.0.96.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Brian Mariani from DigitalCanion SA"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003e\u003cdiv\u003e\u003cdiv\u003e\u003cp\u003eDigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration.\u003c/p\u003e\n\u003cp\u003eThe specific flaw exists within the backup restoration mechanism, which fails to properly validate the paths, file types, integrity, and authenticity of files contained within a restored TGZ archive. The application does not perform file-signature verification before extracting the archive, allowing a specially crafted backup to contain attacker-controlled files.\u003c/p\u003e\n\u003cp\u003eAn attacker with access to the backup SFTP or other configured repository can therefore provide a malicious TGZ archive that, when restored by the system, may place arbitrary files on the underlying Linux system. Depending on the location and permissions of the extracted files, this behavior can potentially be leveraged to achieve \u003cstrong\u003earbitrary code execution with root privileges\u003c/strong\u003e and compromise the underlying virtual machine.\u003c/p\u003e\n\u003cp\u003eThe absence of enforced backup passwords further reduces the protection provided by the backup mechanism and may facilitate unauthorized access to the repository.\u003c/p\u003e\n\u003c/div\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "DigitalCanion has discovered a vulnerability in the backup restoration functionality that allows an attacker with access to the configured backup repository to introduce arbitrary files into the system during restoration.\n\n\n\n\nThe specific flaw exists within the backup restoration mechanism, which fails to properly validate the paths, file types, integrity, and authenticity of files contained within a restored TGZ archive. The application does not perform file-signature verification before extracting the archive, allowing a specially crafted backup to contain attacker-controlled files.\n\n\n\n\nAn attacker with access to the backup SFTP or other configured repository can therefore provide a malicious TGZ archive that, when restored by the system, may place arbitrary files on the underlying Linux system. Depending on the location and permissions of the extracted files, this behavior can potentially be leveraged to achieve arbitrary code execution with root privileges and compromise the underlying virtual machine.\n\n\n\n\nThe absence of enforced backup passwords further reduces the protection provided by the backup mechanism and may facilitate unauthorized access to the repository."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 \u2014 Path Traversal"
                }
              ]
            },
            {
              "capecId": "CAPEC-642",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-642 \u2014 Replace Binaries"
                }
              ]
            },
            {
              "capecId": "CAPEC-150",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-150 \u2014 Collect Data from Common Locations"
                }
              ]
            },
            {
              "capecId": "CAPEC-242",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-242 \u2014 Code Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "USER",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "DIFFUSE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/AU:Y/R:U/V:D/RE:M/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "MODERATE"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 \u2014 Path Traversal",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73 \u2014 External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-494",
                  "description": "CWE-494 \u2014 Download of Code Without Integrity Check",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-345",
                  "description": "CWE-345 \u2014 Insufficient Verification of Data Authenticity",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434 \u2014 Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T08:25:55.051Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://digitalcanion.com/en/security-research/#vendor=mitel\u0026status=cna"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Mitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to Root Code Execution",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-104805",
        "datePublished": "2026-10-05T08:22:08.836Z",
        "dateReserved": "2026-10-02T13:47:44.296Z",
        "dateUpdated": "2026-10-05T12:57:11.157Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104706 (GCVE-0-2026-104706)

    Vulnerability from cvelistv5 – Published: 2026-10-05 08:17 – Updated: 2026-10-05 13:15
    VLAI
    Title
    Mitel MiVoice Office 400 view system files path traversal
    Summary
    DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://<ip>:8443 via menus Administration -> View Logs
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-05 13:15 UTC
    CWE
    • CWE-31 - Path traversal: 'dir\..\..\filename'
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104706",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-05T13:15:08.911993Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-05T13:15:20.353Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "platforms": [
                "Linux"
              ],
              "product": "Mitel MiVoice Office 400",
              "vendor": "Mitel",
              "versions": [
                {
                  "status": "affected",
                  "version": "11.0.96.0"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Brian Mariani from DigitalCanion SA"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://\u0026lt;ip\u0026gt;:8443 via menus Administration -\u0026gt; View Logs"
                }
              ],
              "value": "DigitalCanion has discovered a path traversal vulnerability that allows to view or download sensitive system files over the portal https://\u003cip\u003e:8443 via menus Administration -\u003e View Logs"
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-126",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-126 Path Traversal"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "YES",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "HIGH",
                "providerUrgency": "AMBER",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/AU:Y/U:Amber",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-31",
                  "description": "CWE-31 Path traversal: \u0027dir\\..\\..\\filename\u0027",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-05T08:25:16.221Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://digitalcanion.com/en/security-research/#vendor=mitel\u0026status=cna"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Mitel MiVoice Office 400 view system files path traversal",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-104706",
        "datePublished": "2026-10-05T08:17:15.583Z",
        "dateReserved": "2026-10-02T10:24:42.984Z",
        "dateUpdated": "2026-10-05T13:15:20.353Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104721 (GCVE-0-2026-104721)

    Vulnerability from cvelistv5 – Published: 2026-10-02 13:21 – Updated: 2026-10-02 13:21
    VLAI
    Title
    Logback: Incomplete protection against CVE-2026-19880
    Summary
    Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.4.  This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.
    CWE
    References
    Impacted products
    Vendor Product Version
    QOS.CH Sarl Logback-classic Affected: 0.9.14 , ≤ 1.6.4 (maven)
    Unaffected: 1.6.5 (maven)
    Create a notification for this product.
    Date Public
    2026-08-14 08:09
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "logback-classic"
              ],
              "platforms": [
                "Java"
              ],
              "product": "Logback-classic",
              "vendor": "QOS.CH Sarl",
              "versions": [
                {
                  "lessThanOrEqual": "1.6.4",
                  "status": "affected",
                  "version": "0.9.14",
                  "versionType": "maven"
                },
                {
                  "status": "unaffected",
                  "version": "1.6.5",
                  "versionType": "maven"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Fran\u00e7ois Martin (GitHub: @martinfrancois, https://github.com/martinfrancois)"
            }
          ],
          "datePublic": "2026-08-14T08:09:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an \nMDC-based discriminator value flows unsanitized into a nested \nFileAppender path, letting an attacker who influences that MDC value \n(e.g. via an HTTP header)\n create and append log files outside the intended directory. \u003cp\u003e\u003cbr\u003eThis issue affects Logback-classic: from 0.9.14 through 1.6.4.\u0026nbsp; This vulnerability is similar to CVE-2026-19880 but involves other attack techniques.\u003cbr\u003e\u003cbr\u003e\u003c/p\u003e"
                }
              ],
              "value": "Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an \nMDC-based discriminator value flows unsanitized into a nested \nFileAppender path, letting an attacker who influences that MDC value \n(e.g. via an HTTP header)\n create and append log files outside the intended directory. \n\n\nThis issue affects Logback-classic: from 0.9.14 through 1.6.4.\u00a0 This vulnerability is similar to CVE-2026-19880 but involves other attack techniques."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "No known exploitation\u003cbr\u003e"
                }
              ],
              "value": "No known exploitation"
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "path-traversal vulnerability"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NO",
                "Recovery": "NOT_DEFINED",
                "Safety": "PRESENT",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "GREEN",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:P/AU:N/RE:M/U:Green",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "MODERATE"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T13:21:59.195Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://logback.qos.ch/news.html#1.6.5"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update to logack version 1.6.5 or later.\u0026nbsp;This vulnerability requires\u0026nbsp;\u003ccode\u003eSiftingAppender\u003c/code\u003e\u0026nbsp;to be active as well as unsanitized data provided by an \nattacker that MDCDiscriminator makes use of.\u0026nbsp;\u003cbr\u003e\u003cbr\u003eSanitizing relevant data provided by the user should fix this vulnerability."
                }
              ],
              "value": "Update to logack version 1.6.5 or later.\u00a0This vulnerability requires\u00a0SiftingAppender\u00a0to be active as well as unsanitized data provided by an \nattacker that MDCDiscriminator makes use of.\u00a0\n\nSanitizing relevant data provided by the user should fix this vulnerability."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Logback: Incomplete protection against CVE-2026-19880",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update to logack version 1.6.5 or later.\u0026nbsp;This vulnerability requires\u0026nbsp;\u003ccode\u003eSiftingAppender\u003c/code\u003e\u0026nbsp;to be active as well as unsanitized data provided by an attacker that\u0026nbsp;\u003ccode\u003eMDCDiscriminator\u003c/code\u003e\u0026nbsp;makes use of."
                }
              ],
              "value": "Update to logack version 1.6.5 or later.\u00a0This vulnerability requires\u00a0SiftingAppender\u00a0to be active as well as unsanitized data provided by an attacker that\u00a0MDCDiscriminator\u00a0makes use of."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-104721",
        "datePublished": "2026-10-02T13:21:59.195Z",
        "dateReserved": "2026-10-02T11:43:59.014Z",
        "dateUpdated": "2026-10-02T13:21:59.195Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104733 (GCVE-0-2026-104733)

    Vulnerability from cvelistv5 – Published: 2026-10-02 12:19 – Updated: 2026-10-02 16:57
    VLAI
    Title
    User Impersonation/Authorization Bypass in XMPP Server ejabberd
    Summary
    User Impersonation in ProcessOnes XMMP Server ejabberd <= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 16:56 UTC
    CWE
    • User Impersonation
    • CWE-290 - Authentication Bypass by Spoofing
    References
    Impacted products
    Vendor Product Version
    ProcessOne ejabberd Affected: 0 , ≤ 26.04 (custom)
    Create a notification for this product.
    Date Public
    2026-07-31 09:01
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104733",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T16:56:58.717189Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-290",
                    "description": "CWE-290 Authentication Bypass by Spoofing",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T16:57:18.308Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "MacOS",
                "Linux"
              ],
              "product": "ejabberd",
              "repo": "https://github.com/processone/ejabberd",
              "vendor": "ProcessOne",
              "versions": [
                {
                  "changes": [
                    {
                      "at": "26.07",
                      "status": "unaffected"
                    }
                  ],
                  "lessThanOrEqual": "26.04",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Marius Schwarz (NSIDE ATTACK LOGIC GmbH)"
            }
          ],
          "datePublic": "2026-07-31T09:01:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "User Impersonation in ProcessOnes XMMP Server ejabberd \u0026lt;= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism."
                }
              ],
              "value": "User Impersonation in ProcessOnes XMMP Server ejabberd \u003c= 26.04 allows an attacker to impersonate arbitrary users via unvalidated authzid parameter in SASL-PLAIN mechanism."
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "Authorization Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.4,
                "baseSeverity": "HIGH",
                "exploitMaturity": "PROOF_OF_CONCEPT",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:H/SI:H/SA:H/E:P",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "User Impersonation",
                  "lang": "en"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T12:19:10.635Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://www.nsideattacklogic.de/advisories/NSIDE-SA-2026-004/"
            },
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://github.com/processone/ejabberd/releases#release-26.07"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update to the latest version of ejabberd (26.07)"
                }
              ],
              "value": "Update to the latest version of ejabberd (26.07)"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "User Impersonation/Authorization Bypass in XMPP Server ejabberd",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Disable the SALS-PLAIN authentication mechanism"
                }
              ],
              "value": "Disable the SALS-PLAIN authentication mechanism"
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-104733",
        "datePublished": "2026-10-02T12:19:10.635Z",
        "dateReserved": "2026-10-02T11:49:34.103Z",
        "dateUpdated": "2026-10-02T16:57:18.308Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84830 (GCVE-0-2026-84830)

    Vulnerability from cvelistv5 – Published: 2026-09-03 08:45 – Updated: 2026-09-03 12:32
    VLAI
    Title
    OS command injection in privileged configuration handling
    Summary
    SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-03 12:32 UTC
    CWE
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    • CWE-269 - - Improper Privilege Management
    Impacted products
    Vendor Product Version
    SEPPmail AG Secure Email Gateway Affected: 0 , < 15.0.7 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84830",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-03T12:32:27.907304Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-03T12:32:36.198Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Secure Email Gateway",
              "vendor": "SEPPmail AG",
              "versions": [
                {
                  "lessThan": "15.0.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Emposo GmbH"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges.\u003cbr\u003e"
                }
              ],
              "value": "SEPPmail Secure Email Gateway before 15.0.7 contains a command injection vulnerability that allows authenticated administrators to execute commands with elevated privileges."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-88",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-88 OS Command Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 - Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T08:45:42.216Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "OS command injection in privileged configuration handling",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-84830",
        "datePublished": "2026-09-03T08:45:42.216Z",
        "dateReserved": "2026-09-02T11:31:38.548Z",
        "dateUpdated": "2026-09-03T12:32:36.198Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84832 (GCVE-0-2026-84832)

    Vulnerability from cvelistv5 – Published: 2026-09-03 08:45 – Updated: 2026-09-04 16:52
    VLAI
    Title
    Unsafe deserialization in the REST interface
    Summary
    SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with "nobody" privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-03 12:32 UTC
    CWE
    • CWE-502 - Deserialization of untrusted data
    • CWE-78 - Improper neutralization of special elements used in an OS command ('OS command injection')
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84832",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-03T12:32:58.941461Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-04T16:52:13.072Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SEPPmail Secure Email Gateway (SEG)",
              "vendor": "SEPPmail AG",
              "versions": [
                {
                  "lessThan": "15.0.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Emposo GmbH"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eSEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with \"nobody\" privileges.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "SEPPmail Secure Email Gateway before 15.0.6 deserializes attacker-controlled data in a privileged REST import workflow without adequate validation. An attacker with a privileged API token can execute arbitrary commands with \"nobody\" privileges."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-586",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-586 Object Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.6,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "HIGH",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502 Deserialization of untrusted data",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78 Improper neutralization of special elements used in an OS command (\u0027OS command injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T08:45:08.108Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Unsafe deserialization in the REST interface",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-84832",
        "datePublished": "2026-09-03T08:45:08.108Z",
        "dateReserved": "2026-09-02T11:31:39.643Z",
        "dateUpdated": "2026-09-04T16:52:13.072Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-84831 (GCVE-0-2026-84831)

    Vulnerability from cvelistv5 – Published: 2026-09-03 08:43 – Updated: 2026-09-03 12:34
    VLAI
    Title
    Mandatory MFA bypass before enrollment
    Summary
    SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-03 12:34 UTC
    CWE
    • CWE-287 - - Improper Authentication
    • CWE-306 - Missing authentication for critical function
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-84831",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-03T12:34:12.211918Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-03T12:34:19.659Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "SEPPmail Secure Email Gateway (SEG)",
              "vendor": "SEPPmail AG",
              "versions": [
                {
                  "lessThan": "15.0.7",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Emposo GmbH"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003cspan\u003eSEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor.\u003c/span\u003e\u003c/p\u003e"
                }
              ],
              "value": "SEPPmail Secure Email Gateway before 15.0.7 creates a fully privileged session before required multi-factor authentication enrollment is completed. An attacker with the password for an MFA-required but unenrolled account can access protected functionality without providing a second factor."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-115",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-115 Authentication Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 7.7,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287 - Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing authentication for critical function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-03T08:43:46.501Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://downloads.seppmail.com/extrelnotes/150/ERN15.0.html"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Mandatory MFA bypass before enrollment",
          "x_generator": {
            "engine": "Vulnogram 1.0.4"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-84831",
        "datePublished": "2026-09-03T08:43:46.501Z",
        "dateReserved": "2026-09-02T11:31:39.002Z",
        "dateUpdated": "2026-09-03T12:34:19.659Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-14208 (GCVE-0-2026-14208)

    Vulnerability from cvelistv5 – Published: 2026-08-21 10:51 – Updated: 2026-08-21 11:54
    VLAI
    Title
    Local Privilege Escalation via Insecure DLL Permissions in Remote Utilities Host <=7.7.3.0
    Summary
    Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), granting FULL CONTROL (F) to the built-in Everyone group (BUILTIN\Everyone, S-1-1-0). A Windows service running as NT AUTHORITY\SYSTEM loads DLLs from this directory. The DLLs are file-locked at runtime, but a race window exists when the service is stopped (e.g. during a software update or following a crash), during which a local unprivileged attacker can replace a DLL with a malicious payload. Upon service restart, the payload executes as NT AUTHORITY\SYSTEM. The DLL confirmed as actively loaded during testing is libasset32.dll. Additional DLLs in the same directory (eventmsg.dll, libcodec32.dll, vp8encoder.dll, vp8decoder.dll, webmvorbisdecoder.dll, webmvorbisencoder.dll, webmmux.dll) share identical insecure permissions.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-21 11:54 UTC
    CWE
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    References
    Impacted products
    Vendor Product Version
    Remote Utilities Pte. Ltd. Remote Utilities Host Affected: 0 , ≤ 7.7.3.0 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-14208",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-21T11:54:08.166217Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-21T11:54:27.254Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "platforms": [
                "Windows"
              ],
              "product": "Remote Utilities Host",
              "vendor": "Remote Utilities Pte. Ltd.",
              "versions": [
                {
                  "lessThanOrEqual": "7.7.3.0",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Janik Wehrli of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eRemote Utilities Host \u0026lt;=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\\Program Files (x86)\\Remote Utilities - Host\\), granting FULL CONTROL (F) to the built-in Everyone group (BUILTIN\\Everyone, S-1-1-0). A Windows service running as NT AUTHORITY\\SYSTEM loads DLLs from this directory. The DLLs are file-locked at runtime, but a race window exists when the service is stopped (e.g. during a software update or following a crash), during which a local unprivileged attacker can replace a DLL with a malicious payload. Upon service restart, the payload executes as NT AUTHORITY\\SYSTEM. The DLL confirmed as actively loaded during testing is libasset32.dll. Additional DLLs in the same directory (eventmsg.dll, libcodec32.dll, vp8encoder.dll, vp8decoder.dll, webmvorbisdecoder.dll, webmvorbisencoder.dll, webmmux.dll) share identical insecure permissions.\u003c/p\u003e"
                }
              ],
              "value": "Remote Utilities Host \u003c=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\\Program Files (x86)\\Remote Utilities - Host\\), granting FULL CONTROL (F) to the built-in Everyone group (BUILTIN\\Everyone, S-1-1-0). A Windows service running as NT AUTHORITY\\SYSTEM loads DLLs from this directory. The DLLs are file-locked at runtime, but a race window exists when the service is stopped (e.g. during a software update or following a crash), during which a local unprivileged attacker can replace a DLL with a malicious payload. Upon service restart, the payload executes as NT AUTHORITY\\SYSTEM. The DLL confirmed as actively loaded during testing is libasset32.dll. Additional DLLs in the same directory (eventmsg.dll, libcodec32.dll, vp8encoder.dll, vp8decoder.dll, webmvorbisdecoder.dll, webmvorbisencoder.dll, webmmux.dll) share identical insecure permissions."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-17",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-17: Using Malicious Files"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732: Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-21T10:51:07.262Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "name": "Remote Utilities Pte. Ltd. \u2013 vendor website",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.remoteutilities.com/product/release-notes.php#windows"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003e\u003c/p\u003e\u003col\u003e\u003cli\u003eRemove Everyone:(F) ACL from all DLL files under the installation directory. Restrict to: SYSTEM (Full Control), Administrators (Full Control), Users/Authenticated Users (Read \u0026amp; Execute). Enforce recursively in installer, update routine, and repair mechanism.\u003c/li\u003e\u003cli\u003e\u003cspan\u003eImplement cryptographic signature verification of all loaded DLLs at service startup.\u003c/span\u003e\u003c/li\u003e\u003cli\u003e\u003cspan\u003eUse atomic DLL replacement during updates (write to temp path, verify signature, rename).\u003c/span\u003e\u003c/li\u003e\u003c/ol\u003e\u003cp\u003e\u003c/p\u003e"
                }
              ],
              "value": "*  Remove Everyone:(F) ACL from all DLL files under the installation directory. Restrict to: SYSTEM (Full Control), Administrators (Full Control), Users/Authenticated Users (Read \u0026 Execute). Enforce recursively in installer, update routine, and repair mechanism.\n  *  Implement cryptographic signature verification of all loaded DLLs at service startup.\n  *  Use atomic DLL replacement during updates (write to temp path, verify signature, rename)."
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "timeline": [
            {
              "lang": "en",
              "time": "2026-04-13T00:00:00.000Z",
              "value": "Vulnerability discovered."
            },
            {
              "lang": "en",
              "time": "2026-04-20T00:00:00.000Z",
              "value": "Vendor (Remote Utilities Pte. Ltd.) notified. 90-day coordinated disclosure window communicated."
            },
            {
              "lang": "en",
              "time": "2026-04-20T00:00:00.000Z",
              "value": "NCSC notified, CVE assignment requested."
            },
            {
              "lang": "en",
              "time": "2026-04-21T00:00:00.000Z",
              "value": "Vendor acknowledged the report and confirmed the vulnerability."
            },
            {
              "lang": "en",
              "time": "2026-06-11T00:00:00.000Z",
              "value": "Fix released by the vendor."
            }
          ],
          "title": "Local Privilege Escalation via Insecure DLL Permissions in Remote Utilities Host \u003c=7.7.3.0",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eManually correct DLL ACLs using icacls: icacls \u0026quot;C:\\Program Files (x86)\\Remote Utilities - Host\\*.dll\u0026quot; /remove \u0026quot;Everyone\u0026quot; /grant \u0026quot;BUILTIN\\Users:(RX)\u0026quot; /grant \u0026quot;NT AUTHORITY\\SYSTEM:(F)\u0026quot; /grant \u0026quot;BUILTIN\\Administrators:(F)\u0026quot;\u003c/p\u003e"
                }
              ],
              "value": "Manually correct DLL ACLs using icacls: icacls \"C:\\Program Files (x86)\\Remote Utilities - Host\\*.dll\" /remove \"Everyone\" /grant \"BUILTIN\\Users:(RX)\" /grant \"NT AUTHORITY\\SYSTEM:(F)\" /grant \"BUILTIN\\Administrators:(F)\""
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          },
          "x_notes": "Public reference required by MITRE (CVE CNA Rules section 8.3) is pending. The vendor has confirmed the vulnerability and indicated a fix will be included in the next release. A public changelog or security advisory from the vendor is expected upon patch release and will be added as the formal public reference at that time."
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-14208",
        "datePublished": "2026-08-21T10:51:07.262Z",
        "dateReserved": "2026-06-30T09:38:07.326Z",
        "dateUpdated": "2026-08-21T11:54:27.254Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-19880 (GCVE-0-2026-19880)

    Vulnerability from cvelistv5 – Published: 2026-08-14 14:31 – Updated: 2026-08-14 19:46
    VLAI
    Title
    Incomplete protection against CVE-2025-11226
    Summary
    Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC value (e.g. via an HTTP header) create and append log files outside the intended directory. This issue affects Logback-classic: from 0.9.14 through 1.6.2.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-14 19:46 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    QOS.CH Sarl Logback-classic Affected: 0.9.14 , ≤ 1.6.2 (maven)
    Unaffected: 1.6.3 (maven)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-19880",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-14T19:46:26.570632Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-14T19:46:37.661Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "affected",
              "modules": [
                "logback-classic"
              ],
              "platforms": [
                "Java"
              ],
              "product": "Logback-classic",
              "vendor": "QOS.CH Sarl",
              "versions": [
                {
                  "lessThanOrEqual": "1.6.2",
                  "status": "affected",
                  "version": "0.9.14",
                  "versionType": "maven"
                },
                {
                  "status": "unaffected",
                  "version": "1.6.3",
                  "versionType": "maven"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "York Shen - Yong Shen - PayPal Cyber Security Team (UID 100171)"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an \nMDC-based discriminator value flows unsanitized into a nested \nFileAppender path, letting an attacker who influences that MDC value \n(e.g. via an HTTP header)\n create and append log files outside the intended directory. \u003cp\u003e\u003cbr\u003eThis issue affects Logback-classic: from 0.9.14 through 1.6.2.\u003cbr\u003e\u003cbr\u003e\u003c/p\u003e"
                }
              ],
              "value": "Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an \nMDC-based discriminator value flows unsanitized into a nested \nFileAppender path, letting an attacker who influences that MDC value \n(e.g. via an HTTP header)\n create and append log files outside the intended directory. \n\n\nThis issue affects Logback-classic: from 0.9.14 through 1.6.2."
            }
          ],
          "exploits": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "No known exploitation\u003cbr\u003e"
                }
              ],
              "value": "No known exploitation"
            }
          ],
          "impacts": [
            {
              "descriptions": [
                {
                  "lang": "en",
                  "value": "path-traversal vulnerability"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NO",
                "Recovery": "NOT_DEFINED",
                "Safety": "PRESENT",
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "GREEN",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/S:P/AU:N/RE:M/U:Green",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "MODERATE"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-14T14:31:02.361Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://logback.qos.ch/news.html#1.6.3"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update to logack version 1.6.3 or later.\u0026nbsp;This vulnerability requires \nSiftingAppender to be active as well as unsanitized data provided by an \nattacker that MDCDiscriminator makes use of.\u0026nbsp;\u003cbr\u003e\u003cbr\u003eSanitizing relevant data provided by the user should fix this vulnerability."
                }
              ],
              "value": "Update to logack version 1.6.3 or later.\u00a0This vulnerability requires \nSiftingAppender to be active as well as unsanitized data provided by an \nattacker that MDCDiscriminator makes use of.\u00a0\n\nSanitizing relevant data provided by the user should fix this vulnerability."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Incomplete protection against CVE-2025-11226",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Update to logack version 1.6.3 or later.\u0026nbsp;This vulnerability requires SiftingAppender to be active as well as unsanitized data provided by an attacker that MDCDiscriminator makes use of."
                }
              ],
              "value": "Update to logack version 1.6.3 or later.\u00a0This vulnerability requires SiftingAppender to be active as well as unsanitized data provided by an attacker that MDCDiscriminator makes use of."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-19880",
        "datePublished": "2026-08-14T14:31:02.361Z",
        "dateReserved": "2026-08-14T14:30:11.651Z",
        "dateUpdated": "2026-08-14T19:46:37.661Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-16458 (GCVE-0-2026-16458)

    Vulnerability from cvelistv5 – Published: 2026-08-13 08:31 – Updated: 2026-08-13 14:26
    VLAI
    Title
    Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto
    Summary
    Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 14:25 UTC
    CWE
    Impacted products
    Vendor Product Version
    Oberon microsystems AG ocrypto Affected: 3.0.0 , < 4.0.1 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-16458",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T14:25:41.769110Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T14:26:09.348Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "RSA PKCS#1 v1.5 decryption"
              ],
              "product": "ocrypto",
              "vendor": "Oberon microsystems AG",
              "versions": [
                {
                  "lessThan": "4.0.1",
                  "status": "affected",
                  "version": "3.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Padding oracle attack vulnerability in Oberon microsystem AG\u2019s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.\u003cbr\u003e"
                }
              ],
              "value": "Padding oracle attack vulnerability in Oberon microsystem AG\u2019s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-621",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-621 Analysis of Packet Timing and Sizes"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-208",
                  "description": "CWE-208 Observable timing discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-327",
                  "description": "CWE-327",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-13T08:31:39.341Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://www.oberon.ch/security-advisories/cve-2026-16458/"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "Timing side-channel in RSA PKCS#1 v1.5 decryption in ocrypto",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-16458",
        "datePublished": "2026-08-13T08:31:39.341Z",
        "dateReserved": "2026-07-21T11:21:05.979Z",
        "dateUpdated": "2026-08-13T14:26:09.348Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-16459 (GCVE-0-2026-16459)

    Vulnerability from cvelistv5 – Published: 2026-08-13 08:29 – Updated: 2026-08-13 14:24
    VLAI
    Title
    Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto
    Summary
    Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-13 14:23 UTC
    CWE
    Impacted products
    Vendor Product Version
    Oberon microsystems AG Oberon PSA Crypto Affected: 1.0.0 , < 2.1.1 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-16459",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-13T14:23:40.335179Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-13T14:24:15.253Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "RSA PKCS#1 v1.5 decryption"
              ],
              "product": "Oberon PSA Crypto",
              "vendor": "Oberon microsystems AG",
              "versions": [
                {
                  "lessThan": "2.1.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Padding oracle attack vulnerability in Oberon microsystem AG\u2019s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations.\u003cbr\u003e"
                }
              ],
              "value": "Padding oracle attack vulnerability in Oberon microsystem AG\u2019s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an attacker to recover plaintexts via timing measurements of RSA PKCS#1 v1.5 decrypt operations."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-621",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-621 Analysis of Packet Timing and Sizes"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-208",
                  "description": "CWE-208 Observable timing discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-327",
                  "description": "CWE-327",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-13T08:29:07.388Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "url": "https://www.oberon.ch/security-advisories/cve-2026-16459/"
            }
          ],
          "source": {
            "discovery": "UPSTREAM"
          },
          "title": "Timing side-channel in RSA PKCS#1 v1.5 decryption in Oberon PSA Crypto",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-16459",
        "datePublished": "2026-08-13T08:29:07.388Z",
        "dateReserved": "2026-07-21T11:21:06.418Z",
        "dateUpdated": "2026-08-13T14:24:15.253Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54205 (GCVE-0-2026-54205)

    Vulnerability from cvelistv5 – Published: 2026-08-07 10:02 – Updated: 2026-09-07 12:48
    VLAI
    Title
    TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in link storing functionality
    Summary
    Tobit Laboratories AG TeamDavid's Webbox 's link storing functionality (//ServerClient_celink.htm) accepts a “pathname” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables authenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathname” parameter is possible without authentication. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 11:10 UTC
    CWE
    • CWE-20 - Improper input validation
    • CWE-918 - Server-Side request forgery (SSRF)
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54205",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T11:10:03.274543Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T11:19:35.040Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dario Weiss of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox \u0027s link storing functionality (//ServerClient_celink.htm)\n accepts a \u201cpathname\u201d parameter, which can be set to network locations \nusing UNC paths (e.g., \u201c\\\\Server\\Share\u201d). The server processes these \npaths without validation, resulting in outbound connection attempts to \nattacker-controlled SMB servers. This enables authenticated attackers to\n trigger the server to authenticate to arbitrary SMB endpoints, \npotentially exposing NTLM authentication information (such as NTLM \nhashes). If outbound connections to port 445 (SMB) are permitted, \nattackers can use this to conduct SMB relay or credential theft attacks.\n Exploitation of the \u201cpathname\u201d parameter is possible without \nauthentication.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox \u0027s link storing functionality (//ServerClient_celink.htm)\n accepts a \u201cpathname\u201d parameter, which can be set to network locations \nusing UNC paths (e.g., \u201c\\\\Server\\Share\u201d). The server processes these \npaths without validation, resulting in outbound connection attempts to \nattacker-controlled SMB servers. This enables authenticated attackers to\n trigger the server to authenticate to arbitrary SMB endpoints, \npotentially exposing NTLM authentication information (such as NTLM \nhashes). If outbound connections to port 445 (SMB) are permitted, \nattackers can use this to conduct SMB relay or credential theft attacks.\n Exploitation of the \u201cpathname\u201d parameter is possible without \nauthentication.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper input validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918 Server-Side request forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T12:48:14.526Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Server-Side Request Forgery (SSRF) via \u0027pathname\u0027 parameter in link storing functionality",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54205",
        "datePublished": "2026-08-07T10:02:28.928Z",
        "dateReserved": "2026-06-12T09:32:44.532Z",
        "dateUpdated": "2026-09-07T12:48:14.526Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54218 (GCVE-0-2026-54218)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:49 – Updated: 2026-09-07 13:03
    VLAI
    Title
    TeamDavid: Weak Cryptography and Insecure Password Storage
    Summary
    Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox. For users created locally in David, passwords are stored in various files using only obfuscation. Any user with access to the server’s file system, or who can otherwise extract files from the server (see vulnerability “Random File Read”), can potentially obtain affected users’ passwords. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 11:22 UTC
    CWE
    • CWE-321 - Use of hard-coded cryptographic key
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54218",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T11:22:20.906417Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T11:22:37.650Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Lucas Dodgson of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid\u0027s Webbox. For users created locally in David, passwords are stored in various \nfiles using only obfuscation. Any user with access to the server\u2019s file \nsystem, or who can otherwise extract files from the server (see \nvulnerability\u0026nbsp;\u201cRandom File Read\u201d), can potentially obtain affected \nusers\u2019 passwords.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid\u0027s Webbox. For users created locally in David, passwords are stored in various \nfiles using only obfuscation. Any user with access to the server\u2019s file \nsystem, or who can otherwise extract files from the server (see \nvulnerability\u00a0\u201cRandom File Read\u201d), can potentially obtain affected \nusers\u2019 passwords.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-321",
                  "description": "CWE-321 Use of hard-coded cryptographic key",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T13:03:59.486Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Weak Cryptography and Insecure Password Storage",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54218",
        "datePublished": "2026-08-07T09:49:24.052Z",
        "dateReserved": "2026-06-12T09:32:46.515Z",
        "dateUpdated": "2026-09-07T13:03:59.486Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54217 (GCVE-0-2026-54217)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:49 – Updated: 2026-09-07 13:02
    VLAI
    Title
    TeamDavid: Stored XSS in web application
    Summary
    Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to a stored XSS vulnerability. An attacker can send an email containing malicious JavaScript code. When a user accesses the email, the stored cross-site scripting is triggered. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 11:22 UTC
    CWE
    • CWE-20 - Improper input validation
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54217",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T11:22:54.882614Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T11:23:53.681Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dario Weiss of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application is vulnerable to a stored XSS vulnerability. An \nattacker can send an email containing malicious JavaScript code. When a \nuser accesses the email, the stored cross-site scripting is triggered.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application is vulnerable to a stored XSS vulnerability. An \nattacker can send an email containing malicious JavaScript code. When a \nuser accesses the email, the stored cross-site scripting is triggered.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper input validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T13:02:59.417Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Stored XSS in web application",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54217",
        "datePublished": "2026-08-07T09:49:02.019Z",
        "dateReserved": "2026-06-12T09:32:46.514Z",
        "dateUpdated": "2026-09-07T13:02:59.417Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54216 (GCVE-0-2026-54216)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:48 – Updated: 2026-09-07 13:02
    VLAI
    Title
    TeamDavid: Reflected Cross Site Scripting (XSS) via the 'EntryInfo' parameter
    Summary
    Tobit Laboratories AG TeamDavid's Webbox application contains a reflected cross-site scripting (XSS) vulnerability. By sending a specially crafted link including an arbitrary path, an XSS payload or the parameter “EntryInfo”, and the parameter “!templateName=entryMail”, an attacker can cause the payload to execute in the victim’s browser when they click the link. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 11:24 UTC
    CWE
    • CWE-79 - Improper neutralization of input during web page generation ('cross-site scripting')
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54216",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T11:24:10.712764Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T11:24:31.038Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dario Weiss of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application contains a reflected cross-site scripting (XSS) \nvulnerability. By sending a specially crafted link including an \narbitrary path, an XSS payload or the parameter \u201cEntryInfo\u201d, and the \nparameter \u201c!templateName=entryMail\u201d, an attacker can cause the payload \nto execute in the victim\u2019s browser when they click the link.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application contains a reflected cross-site scripting (XSS) \nvulnerability. By sending a specially crafted link including an \narbitrary path, an XSS payload or the parameter \u201cEntryInfo\u201d, and the \nparameter \u201c!templateName=entryMail\u201d, an attacker can cause the payload \nto execute in the victim\u2019s browser when they click the link.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79 Improper neutralization of input during web page generation (\u0027cross-site scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T13:02:09.991Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Reflected Cross Site Scripting (XSS) via the \u0027EntryInfo\u0027 parameter",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54216",
        "datePublished": "2026-08-07T09:48:46.402Z",
        "dateReserved": "2026-06-12T09:32:46.514Z",
        "dateUpdated": "2026-09-07T13:02:09.991Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54215 (GCVE-0-2026-54215)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:48 – Updated: 2026-09-07 13:01
    VLAI
    Title
    TeamDavid: Open Redirect via the 'replyUrl' parameter
    Summary
    Tobit Laboratories AG TeamDavid's Webbox contains an open redirect vulnerability via the “replyUrl” parameter. An attacker can exploit this vulnerability to craft a URL within the application that, when visited, redirects the user’s browser to an arbitrary third-party site. This can be abused for phishing attacks, where users receive a trusted domain link but are redirected to a phishing website. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 11:24 UTC
    CWE
    • CWE-601 - URL redirection to untrusted site ('open redirect')
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54215",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T11:24:50.530508Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T11:25:12.256Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dario Weiss of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox  contains an open redirect vulnerability via the \n\u201creplyUrl\u201d parameter. An attacker can exploit this vulnerability to \ncraft a URL within the application that, when visited, redirects the \nuser\u2019s browser to an arbitrary third-party site. This can be abused for \nphishing attacks, where users receive a trusted domain link but are \nredirected to a phishing website.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox  contains an open redirect vulnerability via the \n\u201creplyUrl\u201d parameter. An attacker can exploit this vulnerability to \ncraft a URL within the application that, when visited, redirects the \nuser\u2019s browser to an arbitrary third-party site. This can be abused for \nphishing attacks, where users receive a trusted domain link but are \nredirected to a phishing website.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "CWE-601 URL redirection to untrusted site (\u0027open redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T13:01:19.082Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Open Redirect via the \u0027replyUrl\u0027 parameter",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54215",
        "datePublished": "2026-08-07T09:48:16.069Z",
        "dateReserved": "2026-06-12T09:32:46.514Z",
        "dateUpdated": "2026-09-07T13:01:19.082Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54214 (GCVE-0-2026-54214)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:47 – Updated: 2026-09-07 13:00
    VLAI
    Title
    TeamDavid: Header Injection through the 'cType' URL parameter
    Summary
    Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to HTTP header injection through the “cType” URL parameter, which allows arbitrary modification of the Content-Type header in HTTP responses. Because the parameter does not properly restrict control characters such as URL-encoded newlines (“%0a”) or colons, attackers can inject additional headers including extra Location headers into the server’s response. This results e.g. in an open redirect vulnerability. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 11:25 UTC
    CWE
    • CWE-601 - URL redirection to untrusted site ('open redirect')
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54214",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T11:25:40.877413Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T11:26:12.784Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dario Weiss of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application is vulnerable to HTTP header injection through the \n\u201ccType\u201d URL parameter, which allows arbitrary modification of the \nContent-Type header in HTTP responses. Because the parameter does not \nproperly restrict control characters such as URL-encoded newlines \n(\u201c%0a\u201d) or colons, attackers can inject additional headers including \nextra Location headers into the server\u2019s response. This results e.g. in \nan open redirect vulnerability.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application is vulnerable to HTTP header injection through the \n\u201ccType\u201d URL parameter, which allows arbitrary modification of the \nContent-Type header in HTTP responses. Because the parameter does not \nproperly restrict control characters such as URL-encoded newlines \n(\u201c%0a\u201d) or colons, attackers can inject additional headers including \nextra Location headers into the server\u2019s response. This results e.g. in \nan open redirect vulnerability.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-601",
                  "description": "CWE-601 URL redirection to untrusted site (\u0027open redirect\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T13:00:38.211Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Header Injection through the \u0027cType\u0027 URL parameter",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54214",
        "datePublished": "2026-08-07T09:47:55.176Z",
        "dateReserved": "2026-06-12T09:32:46.514Z",
        "dateUpdated": "2026-09-07T13:00:38.211Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54213 (GCVE-0-2026-54213)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:47 – Updated: 2026-09-07 12:59
    VLAI
    Title
    TeamDavid: Denial of Service via endpoint 'internalRestart'
    Summary
    Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of “restarting”, the server shuts completely down. As a result, a remote attacker can trigger a persistent denial of service by shutting down the web server without requiring authentication. Recovery requires manual administrator intervention to restart the service. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: poc Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 13:16 UTC
    CWE
    • CWE-284 - Improper Access Control
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54213",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T13:16:49.553112Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T13:17:54.047Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "exploit"
                ],
                "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dario Weiss of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application exposes a functionality that allows the server to be \nshut down when a specific endpoint (/internalRestart) is accessed. This \nendpoint is accessible to unauthenticated users over the public \nInternet. Instead of \u201crestarting\u201d, the server shuts completely down. As a\n result, a remote attacker can trigger a persistent denial of service by\n shutting down the web server without requiring authentication. Recovery\n requires manual administrator intervention to restart the service.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application exposes a functionality that allows the server to be \nshut down when a specific endpoint (/internalRestart) is accessed. This \nendpoint is accessible to unauthenticated users over the public \nInternet. Instead of \u201crestarting\u201d, the server shuts completely down. As a\n result, a remote attacker can trigger a persistent denial of service by\n shutting down the web server without requiring authentication. Recovery\n requires manual administrator intervention to restart the service.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.2,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284 Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T12:59:55.983Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Denial of Service via endpoint \u0027internalRestart\u0027",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54213",
        "datePublished": "2026-08-07T09:47:34.613Z",
        "dateReserved": "2026-06-12T09:32:46.514Z",
        "dateUpdated": "2026-09-07T12:59:55.983Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54212 (GCVE-0-2026-54212)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:47 – Updated: 2026-09-07 12:58
    VLAI
    Title
    TeamDavid: Buffer Overflow in JSON-parsing
    Summary
    Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker can cause the server to crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially lead to remote code execution and full compromise of the server. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 14:38 UTC
    CWE
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54212",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T14:38:05.213025Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T14:38:27.060Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Lucas Dodgson of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application implements an API endpoint that is vulnerable to a \nbuffer overflow condition. By submitting a specially crafted JSON body, \nsuch as one that is at least 8 characters long and begins with a number,\n an unauthenticated attacker can cause the server to crash, resulting in\n denial of service. Depending on the stack state or if a stack canary \ncan be disclosed through another vulnerability, this buffer overflow \ncould potentially lead to remote code execution and full compromise of \nthe server.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application implements an API endpoint that is vulnerable to a \nbuffer overflow condition. By submitting a specially crafted JSON body, \nsuch as one that is at least 8 characters long and begins with a number,\n an unauthenticated attacker can cause the server to crash, resulting in\n denial of service. Depending on the stack state or if a stack canary \ncan be disclosed through another vulnerability, this buffer overflow \ncould potentially lead to remote code execution and full compromise of \nthe server.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.5,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T12:58:58.837Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Buffer Overflow in JSON-parsing",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54212",
        "datePublished": "2026-08-07T09:47:12.542Z",
        "dateReserved": "2026-06-12T09:32:46.514Z",
        "dateUpdated": "2026-09-07T12:58:58.837Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54211 (GCVE-0-2026-54211)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:46 – Updated: 2026-09-07 12:58
    VLAI
    Title
    TeamDavid: Buffer Overflow in multiple form data parameters
    Summary
    Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in these parameters, an authenticated attacker can trigger a server crash, resulting in denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially be exploited for remote code execution, leading to full compromise of the server. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 14:39 UTC
    CWE
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54211",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T14:39:30.956429Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T14:39:36.097Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dario Weiss of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application\u2019s endpoint \u201c//serverClient_close.html\u201d is vulnerable to a\n buffer overflow vulnerability in multiple form data parameters. By \nsubmitting excessively long values in these parameters, an authenticated\n attacker can trigger a server crash, resulting in denial of service. \nDepending on the stack state or if a stack canary can be disclosed \nthrough another vulnerability, this buffer overflow could potentially be\n exploited for remote code execution, leading to full compromise of the \nserver.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application\u2019s endpoint \u201c//serverClient_close.html\u201d is vulnerable to a\n buffer overflow vulnerability in multiple form data parameters. By \nsubmitting excessively long values in these parameters, an authenticated\n attacker can trigger a server crash, resulting in denial of service. \nDepending on the stack state or if a stack canary can be disclosed \nthrough another vulnerability, this buffer overflow could potentially be\n exploited for remote code execution, leading to full compromise of the \nserver.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.5,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T12:58:13.534Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Buffer Overflow in multiple form data parameters",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54211",
        "datePublished": "2026-08-07T09:46:50.005Z",
        "dateReserved": "2026-06-12T09:32:46.514Z",
        "dateUpdated": "2026-09-07T12:58:13.534Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54210 (GCVE-0-2026-54210)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:46 – Updated: 2026-09-07 12:56
    VLAI
    Title
    TeamDavid: Buffer Overflow in file names of file upload functionalities
    Summary
    Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. By specifying an excessively long filename in a file upload request, an unauthenticated attacker can trigger a crash of the server, resulting in a denial of service. Depending on the stack state or if a stack canary can be disclosed through another vulnerability, this buffer overflow could potentially be exploited for remote code execution, leading to full compromise of the server. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 14:40 UTC
    CWE
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54210",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T14:40:44.292296Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T14:40:53.579Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Lucas Dodgson of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application implements various file upload functionalities that are \nvulnerable to a buffer overflow condition. By specifying an excessively \nlong filename in a file upload request, an unauthenticated attacker can \ntrigger a crash of the server, resulting in a denial of service. \nDepending on the stack state or if a stack canary can be disclosed \nthrough another vulnerability, this buffer overflow could potentially be\n exploited for remote code execution, leading to full compromise of the \nserver.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application implements various file upload functionalities that are \nvulnerable to a buffer overflow condition. By specifying an excessively \nlong filename in a file upload request, an unauthenticated attacker can \ntrigger a crash of the server, resulting in a denial of service. \nDepending on the stack state or if a stack canary can be disclosed \nthrough another vulnerability, this buffer overflow could potentially be\n exploited for remote code execution, leading to full compromise of the \nserver.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.5,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-787",
                  "description": "CWE-787 Out-of-bounds write",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T12:56:54.726Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Buffer Overflow in file names of file upload functionalities",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54210",
        "datePublished": "2026-08-07T09:46:23.246Z",
        "dateReserved": "2026-06-12T09:32:46.514Z",
        "dateUpdated": "2026-09-07T12:56:54.726Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54209 (GCVE-0-2026-54209)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:45 – Updated: 2026-09-07 12:55
    VLAI
    Title
    TeamDavid: Buffer Overflow in 'editini' function
    Summary
    Tobit Laboratories AG TeamDavid's Webbox application handles password changes using a function triggered by including the string "(editini)" in the file path, writing the new password to the specified "Archive.ini" file. However, the application does not verify that the provided path actually refers to an "Archive.ini" file. If an attacker specifies a different file with excessive size, a buffer overflow occurs. This vulnerability allows an unauthenticated attacker to crash the server, resulting in denial of service. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 14:41 UTC
    CWE
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54209",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T14:41:05.833002Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T14:41:12.866Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dario Weiss of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application handles password changes using a function triggered by \nincluding the string \"(editini)\" in the file path, writing the new \npassword to the specified \"Archive.ini\" file. However, the application \ndoes not verify that the provided path actually refers to an \n\"Archive.ini\" file. If an attacker specifies a different file with \nexcessive size, a buffer overflow occurs. This vulnerability allows an \nunauthenticated attacker to crash the server, resulting in denial of \nservice.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application handles password changes using a function triggered by \nincluding the string \"(editini)\" in the file path, writing the new \npassword to the specified \"Archive.ini\" file. However, the application \ndoes not verify that the provided path actually refers to an \n\"Archive.ini\" file. If an attacker specifies a different file with \nexcessive size, a buffer overflow occurs. This vulnerability allows an \nunauthenticated attacker to crash the server, resulting in denial of \nservice.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "HIGH",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.9,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "HIGH",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-125",
                  "description": "CWE-125 Out-of-bounds read",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T12:55:59.027Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Buffer Overflow in \u0027editini\u0027 function",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54209",
        "datePublished": "2026-08-07T09:45:53.568Z",
        "dateReserved": "2026-06-12T09:32:46.514Z",
        "dateUpdated": "2026-09-07T12:55:59.027Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54208 (GCVE-0-2026-54208)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:45 – Updated: 2026-09-07 12:50
    VLAI
    Title
    TeamDavid: Arbitrary File Write leading to Stored XSS
    Summary
    Tobit Laboratories AG TeamDavid's Webbox application is vulnerable to arbitrary file write, allowing an unauthenticated attacker to create or write into existing files on the server with attacker-controlled content. This is possible because user input is written directly to files without proper validation or restriction on file types. As a result, an attacker can create files (e.g., .htm), containing malicious JavaScript code. When a user accesses a file created in this way, stored cross-site scripting is triggered. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 14:41 UTC
    CWE
    • CWE-20 - Improper input validation
    • CWE-284 - Improper Access Control
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54208",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T14:41:23.183708Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T14:41:34.797Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dario Weiss of InfoGuard Labs"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Lucas Dodgson of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application is vulnerable to arbitrary file write, allowing an \nunauthenticated attacker to create or write into existing files on the \nserver with attacker-controlled content. This is possible because user \ninput is written directly to files without proper validation or \nrestriction on file types. As a result, an attacker can create files \n(e.g., .htm), containing malicious JavaScript code. When a user accesses\n a file created in this way, stored cross-site scripting is triggered.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox application is vulnerable to arbitrary file write, allowing an \nunauthenticated attacker to create or write into existing files on the \nserver with attacker-controlled content. This is possible because user \ninput is written directly to files without proper validation or \nrestriction on file types. As a result, an attacker can create files \n(e.g., .htm), containing malicious JavaScript code. When a user accesses\n a file created in this way, stored cross-site scripting is triggered.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "LOW",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "HIGH",
                "userInteraction": "PASSIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper input validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284 Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T12:50:28.360Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Arbitrary File Write leading to Stored XSS",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54208",
        "datePublished": "2026-08-07T09:45:40.088Z",
        "dateReserved": "2026-06-12T09:32:44.532Z",
        "dateUpdated": "2026-09-07T12:50:28.360Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54207 (GCVE-0-2026-54207)

    Vulnerability from cvelistv5 – Published: 2026-08-07 09:45 – Updated: 2026-09-07 12:49
    VLAI
    Title
    TeamDavid: Server-Side Request Forgery (SSRF) via 'pathname' parameter in move archive functionality
    Summary
    Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables au-thenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathname” parameter is possible without authentication. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-07 14:41 UTC
    CWE
    • CWE-20 - Improper input validation
    • CWE-918 - Server-Side request forgery (SSRF)
    Impacted products
    Vendor Product Version
    Tobit Laboratories AG TeamDavid Affected: 0 , < Rollout 528 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54207",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-07T14:41:45.475425Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-07T14:46:24.355Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "modules": [
                "Webbox"
              ],
              "product": "TeamDavid",
              "vendor": "Tobit Laboratories AG",
              "versions": [
                {
                  "lessThan": "Rollout 528",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Dario Weiss of InfoGuard Labs"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox \u0027s move archive functionality (\u201c!ArcEntryMove\u201d) accepts \nan arbitrary path, which can be set to network locations using UNC paths\n (e.g., \u201c\\\\Server\\Share\u201d). The server processes these paths without \nvalidation, resulting in outbound connection attempts to \nattacker-controlled SMB servers. This enables au-thenticated attackers \nto trigger the server to authenticate to arbitrary SMB endpoints, \npotentially exposing NTLM authentication information (such as NTLM \nhashes). If outbound connections to port 445 (SMB) are permitted, \nattackers can use this to conduct SMB relay or credential theft attacks.\n Exploitation of the \u201cpathname\u201d parameter is possible without \nauthentication.\u0026nbsp;\u003cdiv\u003e\u003cdiv\u003e\u003cspan\u003eThis issue affects TeamDavid before Rollout 528.\u003c/span\u003e\u003c/div\u003e\u003cdiv\u003e\u003cspan\u003eStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.\u003c/span\u003e\u003c/div\u003e\u003c/div\u003e"
                }
              ],
              "value": "Tobit Laboratories AG TeamDavid\u0027s Webbox \u0027s move archive functionality (\u201c!ArcEntryMove\u201d) accepts \nan arbitrary path, which can be set to network locations using UNC paths\n (e.g., \u201c\\\\Server\\Share\u201d). The server processes these paths without \nvalidation, resulting in outbound connection attempts to \nattacker-controlled SMB servers. This enables au-thenticated attackers \nto trigger the server to authenticate to arbitrary SMB endpoints, \npotentially exposing NTLM authentication information (such as NTLM \nhashes). If outbound connections to port 445 (SMB) are permitted, \nattackers can use this to conduct SMB relay or credential theft attacks.\n Exploitation of the \u201cpathname\u201d parameter is possible without \nauthentication.\u00a0This issue affects TeamDavid before Rollout 528.\n\nStarting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 6.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "HIGH",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper input validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-918",
                  "description": "CWE-918 Server-Side request forgery (SSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T12:49:39.464Z",
            "orgId": "455daabc-a392-441d-aa46-37d35189897c",
            "shortName": "NCSC.ch"
          },
          "references": [
            {
              "tags": [
                "release-notes"
              ],
              "url": "https://chayns.net/77892-10814/tapp/763210?postId=11454"
            },
            {
              "tags": [
                "third-party-advisory"
              ],
              "url": "https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "TeamDavid: Server-Side Request Forgery (SSRF) via \u0027pathname\u0027 parameter in move archive functionality",
          "x_generator": {
            "engine": "Vulnogram 1.0.2"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "455daabc-a392-441d-aa46-37d35189897c",
        "assignerShortName": "NCSC.ch",
        "cveId": "CVE-2026-54207",
        "datePublished": "2026-08-07T09:45:18.704Z",
        "dateReserved": "2026-06-12T09:32:44.532Z",
        "dateUpdated": "2026-09-07T12:49:39.464Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }