CVE-2026-54203
Last modified
CVE-2026-54203 is a critical-severity vulnerability rated 9.2/10 on the CVSS scale. Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with memory. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with memory. By repeatedly requesting this endpoint, an attacker can access sensitive information, including user passwords. Exploitation does not require authentication. This issue affects TeamDavid through Rollout 524.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Tobit Laboratories AG | TeamDavid | <= Rollout 524 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-54203?
How severe is CVE-2026-54203?
How do I fix CVE-2026-54203?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54198Unauthenticated Cross Site Scripting (XSS) in Media LIbrary …7.1
- CVE-2026-54199Tobit Laboratories AG TeamDavid's Webbox is vulnerable to H…5.3
- CVE-2026-5420A security flaw has been discovered in Shinrays Games Goods …2.5
- CVE-2026-54200Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a…8.4
- CVE-2026-54201Tobit Laboratories AG TeamDavid's Webbox does not enforce a…6.9
- CVE-2026-54202Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a…8.5
- CVE-2026-54204Tobit Laboratories AG TeamDavid's Webbox 's search functiona…7.7
- CVE-2026-54205Tobit Laboratories AG TeamDavid's Webbox 's link storing fun…6.3
- CVE-2026-54206Tobit Laboratories AG TeamDavid's Webbox 's sending email, f…6.3
- CVE-2026-54207Tobit Laboratories AG TeamDavid's Webbox 's move archive fun…6.3
- CVE-2026-54208Tobit Laboratories AG TeamDavid's Webbox application is vuln…8.5
- CVE-2026-54209Tobit Laboratories AG TeamDavid's Webbox application handles…8.9
Are you affected by CVE-2026-54203?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
