What is CVE-2026-54206?
CVE-2026-54206 is a vulnerability in Tobit Laboratories AG TeamDavids Webbox where the email, fax, and SMS sending functionality allows a @@INCLUDE command with unvalidated UNC paths. This can force the server to initiate outbound connections to arbitrary network shares, posing risks of data exfiltration or internal network reconnaissance. Mitigation involves strictly validating user-supplied input to the @@INCLUDE function.
Azərbaycanca: CVE-2026-54206, Tobit Laboratories AG-nin TeamDavids Webbox məhsulunda e-poçt, faks, SMS göndərmə funksionallığında aşkarlanmış boşluqdur. Zəiflik @@INCLUDE əmri vasitəsilə təsdiqlənməmiş UNC yol qəbuluna imkan verir və serverin ixtiyari şəbəkə resurslarına çıxış cəhdi etməsinə səbəb olur. Bu vəziyyət potensial məlumat sızması və ya daxili şəbəkə kəşfiyyatı riskləri yaradır; @@INCLUDE funksiyasına istifadəçi tərəfindən verilən girişlərin ciddi şəkildə yoxlanılması tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Tobit Laboratories AG
FAQ2
Which product from Tobit Laboratories AG is affected by CVE-2026-54206?
The TeamDavids Webbox product from Tobit Laboratories AG.
What can an attacker achieve by exploiting CVE-2026-54206?
They can force the server to initiate outbound connections to arbitrary network shares, posing risks of data exfiltration or internal network reconnaissance.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.