Description
Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot”
parameter, which can be set to network locations using UNC paths (e.g.,
“\\Server\Share”). The server processes these paths without validation,
resulting in outbound connection attempts to attacker-controlled SMB
servers. This enables unauthenticated attackers to trigger the server to
authenticate to arbitrary SMB endpoints, potentially exposing NTLM
authentication information (such as NTLM hashes). If outbound
connections to port 445 (SMB) are permitted, attackers can use this to
conduct SMB relay or credential theft attacks. Exploitation of the
“pathnameroot” parameter is possible without authentication.This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Published: 2026-08-07
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Credential Exposure via SSRF
Action: Patch Immediately
AI Analysis

Impact

The flaw originates from the TeamDavid websearch feature’s ‘pathnameroot’ parameter, which accepts UNC paths without validation. When an attacker supplies a path such as `\\Server\\Share`, the server attempts to connect to that SMB share on port 445, automatically authenticating with NTLM and potentially leaking NTLM hashes. This Server‑Side Request Forgery can therefore expose the server’s credentials and enable credential‑stealing or SMB‑relay attacks. The vulnerability is fully exploitable without authentication and is categorized as CWE‑20 and CWE‑918, with a CVSS score of 7.7 indicating significant risk.

Affected Systems

Affected installations of the Tobit Laboratories AG TeamDavid platform are those that have not yet migrated to Rollout 528 (June 30 2026). In that release the search functionality that accepts a ‘pathnameroot’ parameter is disabled by default, removing the SSRF surface; therefore systems on or after Rollout 528 are no longer exposed to this flaw.

Risk and Exploitability

An attacker can trigger the SSRF by sending a crafted search request containing a UNC path. No authentication is required, and if outbound SMB traffic is permitted, the server may authenticate to a remote SMB endpoint, allowing the attacker to capture NTLM hashes or use the machine as a relay for further attacks. The EPSS score of less than 1 % indicates a very low but non‑zero likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The risk level is therefore moderate to high for pre‑Rollout 528 installations, but it effectively disappears for newer versions where the functionality is disabled by default.

Generated by OpenCVE AI on September 7, 2026 at 15:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Tobit Laboratories’ release notes and upgrade to a version of TeamDavid that addresses the UNC path validation flaw (addressing CWE‑20).
  • Configure network or firewall rules to block outbound SMB traffic (port 445) from the TeamDavid Webbox to prevent the server from connecting to external SMB endpoints, mitigating the SSRF weakness (CWE‑918).
  • If an immediate upgrade is not feasible, restrict unauthenticated access to the search functionality or remove the ability to supply UNC paths by removing or disabling the ‘pathnameroot’ parameter, thereby preventing the input validation flaw (CWE‑20).

Generated by OpenCVE AI on September 7, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables unauthenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathnameroot” parameter is possible without authentication. This issue affects TeamDavid through Rollout 524. Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables unauthenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathnameroot” parameter is possible without authentication.This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
References

Sat, 08 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox 's search functionality accepts a “pathnameroot” parameter, which can be set to network locations using UNC paths (e.g., “\\Server\Share”). The server processes these paths without validation, resulting in outbound connection attempts to attacker-controlled SMB servers. This enables unauthenticated attackers to trigger the server to authenticate to arbitrary SMB endpoints, potentially exposing NTLM authentication information (such as NTLM hashes). If outbound connections to port 445 (SMB) are permitted, attackers can use this to conduct SMB relay or credential theft attacks. Exploitation of the “pathnameroot” parameter is possible without authentication. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Server-Side Request Forgery (SSRF) via 'pathnameroot' parameter in search functionality
Weaknesses CWE-20
CWE-918
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-09-07T12:47:29.060Z

Reserved: 2026-06-12T09:32:44.532Z

Link: CVE-2026-54204

cve-icon Vulnrichment

Updated: 2026-08-07T14:46:44.652Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T10:16:57.207

Modified: 2026-09-07T13:20:26.573

Link: CVE-2026-54204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:15:17Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-918

    Server-Side Request Forgery (SSRF)