Description
Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks
when serving these log files. As a result, attackers can obtain
sensitive error information or internal application details, potentially
aiding in further attacks. This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Published: 2026-08-07
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of sensitive error and internal application details
Action: Apply Patch
AI Analysis

Impact

Tobit Laboratories AG’s TeamDavid Webbox lacks authentication or authorization checks when serving log files, allowing any user to retrieve detailed error messages and internal data. The exposed information can aid an attacker in mapping the application or identifying additional weaknesses, potentially facilitating further attacks.

Affected Systems

The vulnerability affects the TeamDavid Webbox component of Tobit Laboratories AG, specifically versions released before Rollout 528. All deployments that expose the default log‑file endpoints in those versions are impacted.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS score is 0.00324 (approximately 0.3%), showing very low but nonzero exploitation probability. The issue is not listed in CISA KEV. Attackers can exploit the flaw remotely by simply accessing the exposed URLs without authentication, making the threat relatively low‑cost but potentially valuable for reconnaissance. This attack is only possible on versions before Rollout 528, since the functionality is disabled by default thereafter. Due to the lack of preventative checks, the exploitability is high for any system exposing the default log‑file routes over the network.

Generated by OpenCVE AI on September 7, 2026 at 15:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TeamDavid to the latest release that enforces authorization on log file endpoints
  • If an immediate update is not possible, disable or secure the log file endpoints by requiring authentication or removing the exposed routes
  • Restrict network access to the Webbox so that only trusted hosts can reach the log file URLs

Generated by OpenCVE AI on September 7, 2026 at 15:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these log files. As a result, attackers can obtain sensitive error information or internal application details, potentially aiding in further attacks. This issue affects TeamDavid through Rollout 524. Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these log files. As a result, attackers can obtain sensitive error information or internal application details, potentially aiding in further attacks. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
References

Mon, 10 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 08 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox does not enforce authentication or authorization checks when serving these log files. As a result, attackers can obtain sensitive error information or internal application details, potentially aiding in further attacks. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Missing Authorization
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-09-07T12:45:29.829Z

Reserved: 2026-06-12T09:32:44.531Z

Link: CVE-2026-54201

cve-icon Vulnrichment

Updated: 2026-08-10T11:33:38.879Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T10:16:56.790

Modified: 2026-09-07T13:20:25.317

Link: CVE-2026-54201

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T16:00:13Z

Weaknesses