Hard-Coded Cryptographic Key Issue in Tobit Laboratories AG TeamDavid Product
CVE-2026-54218

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
7 August 2026

What is CVE-2026-54218?

A security flaw has been identified in Tobit Laboratories AG's TeamDavid product, where locally created users' passwords are stored using embedded cryptographic keys and obfuscation methods. This vulnerability allows unauthorized individuals who gain access to the server's file system or are capable of extracting files to potentially recover sensitive passwords. The issue impacts the TeamDavid software version Rollout 524, raising significant concerns regarding user data integrity and application security.

Affected Version(s)

TeamDavid 0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucas Dodgson of InfoGuard Labs
.