CVE-2026-54202: TeamDavid: Path Traversal in the archive creation functionality
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently validated, an attacker can manipulate the input to traverse directories. This allows the creation of folders in arbitrary locations, including sensitive directories such as C:\Windows or for different users. This issue affects TeamDavid through Rollout 524.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54202?
CVE-2026-54202 has a risk rating of 48, indicating it is a moderate vulnerability.
How do I fix CVE-2026-54202?
To fix CVE-2026-54202, ensure proper validation and sanitization of user inputs in the archive creation functionality.
What software is affected by CVE-2026-54202?
CVE-2026-54202 affects TeamDavid's Webbox.
What type of vulnerability is CVE-2026-54202?
CVE-2026-54202 is a path traversal vulnerability.
When was CVE-2026-54202 published?
CVE-2026-54202 was published on August 7, 2026.