CRITICAL 9.2 NVD
CVE-2026-54203
Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “
Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds
with memory. By repeatedly
requesting this endpoint, an attacker can access sensitive
information, including user passwords. Exploitation does not require
authentication. This issue affects TeamDavid through Rollout 524.
References
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-08-07 via NVD.
Risk Timeline
CVE Disclosed2026-08-07 · 2 days ago
Remediation Resources
Official Advisory
david.tobit.software/releasenotesOfficial Advisory
labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.