CRITICAL 9.2 NVD
CVE-2026-54213
Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart)
Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be
shut down when a specific endpoint (/internalRestart) is accessed. This
endpoint is accessible to unauthenticated users over the public
Internet. Instead of “restarting”, the server shuts completely down. As a
result, a remote attacker can trigger a persistent denial of service by
shutting down the web server without requiring authentication. Recovery
requires manual administrator intervention to restart the service. This issue affects TeamDavid through Rollout 524.
References
- https://david.tobit.software/releasenotes
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
- https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
This critical severity vulnerability with a CVSS score of 9.2 was published on 2026-08-07 via NVD.
Risk Timeline
CVE Disclosed2026-08-07 · 2 days ago
Remediation Resources
Official Advisory
david.tobit.software/releasenotesOfficial Advisory
labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.