# CVE-2026-54202

## Summary

- **CVE ID:** CVE-2026-54202
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H)
- **CWE:** CWE-36
- **Published:** Aug 7, 2026
- **Last Modified:** Sep 7, 2026

## Description

Tobit Laboratories AG TeamDavid's Webbox  is vulnerable to a path traversal vulnerability in the 
archive creation functionality. Because the archive path is 
user-controlled and insufficiently validated, an attacker can manipulate
 the input to traverse directories. This allows the creation of folders 
in arbitrary locations, including sensitive directories such as 
C:\Windows or for different users. This issue affects TeamDavid through Rollout 524.

## Affected Products

- Tobit Laboratories AG — TeamDavid (0)

## References

- [CNA](https://david.tobit.software/releasenotes)
- [CNA](https://labs.infoguard.ch/posts/22-cves-in-david-a-secure-m365-alternative/)
- [CNA](https://chayns.net/77892-10814/tapp/763210?postId=11454)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.30%
- **EPSS Percentile:** 22.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._