InfoGuard Labs disclosed 22 vulnerabilities in Tobit.Software's TeamDavid collaboration and messaging platform, a product marketed as a secure Microsoft 365 alternative and reportedly exposed on about 12,000 internet-accessible instances. The findings span two disclosure rounds and include unauthenticated denial of service, memory disclosure, buffer overflows, open redirect, HTTP header injection, SSRF via UNC paths, path traversal, arbitrary file deletion and write, stored XSS, and missing authorization. Researchers said the most serious attack chain abused a heap memory leak in the unauthenticated /.well-known/mta-sts. endpoint together with reversibly stored passwords in access.ini files, allowing attackers to recover credentials and access user mailboxes without prior authentication.
One of the newly tracked flaws, CVE-2026-54200, affects TeamDavid Webbox through Rollout 524 and allows authenticated local file inclusion through the scjob form field in email, fax, and SMS functions. By using the @@attach mechanism and bypassing folder protections with alternate data streams, an attacker can attach and retrieve arbitrary files, including other users' access files containing passwords and the server's private key. InfoGuard said Tobit was notified in December, reported partial fixes in late January, and a retest found some remediations were incomplete while uncovering nine additional issues, leaving organizations running TeamDavid at risk of mailbox compromise, sensitive file exposure, forced SMB authentication, server crashes, and possible escalation toward full system compromise.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
InfoGuard Labs publicly disclosed 22 vulnerabilities in TeamDavid, including issues that could enable mailbox compromise, denial of service, file access, SSRF, and potential escalation toward full system compromise.
A CVE entry was published for CVE-2026-54200, a high-severity local file inclusion flaw in TeamDavid Webbox through Rollout 524 that lets an authenticated user abuse the scjob field and @@attach command to access arbitrary files.
According to the researchers, Tobit.Software reported partial fixes by late January following the initial disclosure round.
InfoGuard Labs said it notified the vendor in December after identifying vulnerabilities in TeamDavid during an external penetration test and manual analysis.
A follow-up assessment found some remediations were incomplete and uncovered nine additional vulnerabilities, contributing to a total of 22 reported issues.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.