PT-2026-68900 · Teamdavid · Teamdavid

·

CVE-2026-54204

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TeamDavid versions prior to Rollout 525
Description The search functionality of the Webbox component allows unauthenticated users to provide a pathnameroot parameter containing Universal Naming Convention (UNC) paths. Because the server does not validate these paths, it attempts to establish outbound connections to arbitrary SMB servers. This behavior can lead to the exposure of NTLM authentication hashes, which attackers may use for credential theft or SMB relay attacks if outbound traffic on port 445 is permitted.
Recommendations Update TeamDavid to a version later than Rollout 524. Restrict outbound connections on port 445 to prevent the server from connecting to unauthorized SMB endpoints.

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54204

Affected Products

Teamdavid