CVE-2026-54199
Last modified
CVE-2026-54199 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing functionality (//ServerClient_celink.htm), which is appended to the redirect target in the 302 HTTP response. If a line feed is added, this will also be added to the redirect link, resulting in the ability to control the response headers. This issue affects TeamDavid through Rollout 524.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to HTTP header injection through the request body in the application's link storing functionality (//ServerClient_celink.htm), which is appended to the redirect target in the 302 HTTP response. If a line feed is added, this will also be added to the redirect link, resulting in the ability to control the response headers. This issue affects TeamDavid through Rollout 524.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Tobit Laboratories AG | TeamDavid | <= Rollout 524 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-54199?
How severe is CVE-2026-54199?
How do I fix CVE-2026-54199?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54193Contributor Arbitrary File Deletion in Fusion Builder <= 3.1…7.7
- CVE-2026-54194Contributor PHP Object Injection in Fusion Builder <= 3.15.4…9.8
- CVE-2026-54195Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder…7.1
- CVE-2026-54196Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 v…6.8
- CVE-2026-54197Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1…6.5
- CVE-2026-54198Unauthenticated Cross Site Scripting (XSS) in Media LIbrary …7.1
- CVE-2026-5420A security flaw has been discovered in Shinrays Games Goods …2.5
- CVE-2026-54200Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a…8.4
- CVE-2026-54201Tobit Laboratories AG TeamDavid's Webbox does not enforce a…6.9
- CVE-2026-54202Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a…8.5
- CVE-2026-54203Memory Leak to an Unauthorized Actor vulnerability in Tobit …9.2
- CVE-2026-54204Tobit Laboratories AG TeamDavid's Webbox 's search functiona…7.7
Are you affected by CVE-2026-54199?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
