What is CVE-2026-54207?
This vulnerability exists in the archive move functionality (!ArcEntryMove) of Tobit Laboratories AG's TeamDavid Webbox. An attacker can specify a UNC path, causing the server to initiate unauthorized outbound connections to remote network shares, potentially leading to data leakage. Immediate access control measures should be implemented.
Azərbaycanca: Bu boşluq Tobit Laboratories AG-nin TeamDavid Webbox məhsulunun arxiv daşıma funksiyasında (!ArcEntryMove) aşkarlanıb. İstifadəçi UNC yolunu təyin edərək serveri uzaq şəbəkə resurslarına icazəsiz qoşulmağa məcbur edə bilər, bu da məlumat sızmasına səbəb ola bilər. Dərhal giriş nəzarəti tədbirlərini tətbiq etmək lazımdır.
Related CVEs
link basis: same weakness class CWE-918; shared vendor: Tobit Laboratories AG
FAQ2
Where does the CVE-2026-54207 vulnerability exist in TeamDavid Webbox?
This vulnerability exists in the product's archive move functionality (!ArcEntryMove).
What type of path can an attacker specify to exploit CVE-2026-54207?
An attacker can specify a UNC path, causing the server to initiate unauthorized outbound connections to remote network shares.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.