AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-54202

HIGH · CVSS 8.5 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A path traversal vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows attackers to manipulate user-controlled input to create folders in arbitrary locations, potentially compromising sensitive directories like C:\Windows. This high-severity flaw (CVSS 8.5) poses significant risks to Windows environments running affected versions of TeamDavid, particularly those using Rollout 524. Organizations utilizing this software should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-54202
Severity
HIGH
CVSS
8.5
EPSS
0.30%
Windows

Original NVD Description

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently validated, an attacker can manipulate the input to traverse directories. This allows the creation of folders in arbitrary locations, including sensitive directories such as C:\Windows or for different users. This issue affects TeamDavid through Rollout 524.