Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network… (CVE-2026-54207)
Tobit Laboratories AG TeamDavid's Webbox contains a vulnerability in its move archive functionality (!ArcEntryMove) that accepts arbitrary paths, including network UNC paths. This lack of validation allows unauthenticated attackers to cause the server to initiate outbound SMB connections to attacker-controlled servers. Such connections can lead to exposure of NTLM authentication information, enabling SMB relay or credential theft attacks if outbound SMB traffic is permitted. The issue affects TeamDavid through Rollout 524.
AI Analysis
Technical Summary
The move archive functionality (!ArcEntryMove) in Tobit Laboratories AG TeamDavid's Webbox accepts arbitrary path inputs without validation, including UNC network paths (e.g., \\Server\Share). This causes the server to make outbound SMB connection attempts to attacker-controlled endpoints. Because these connections can trigger NTLM authentication, attackers can potentially capture NTLM hashes or perform SMB relay attacks. Exploitation is possible without authentication. The vulnerability is identified as CVE-2026-54207 and affects versions through Rollout 524.
Potential Impact
An attacker can cause the vulnerable server to authenticate to arbitrary SMB servers controlled by the attacker, potentially exposing NTLM authentication credentials such as hashes. This can facilitate SMB relay attacks or credential theft. The vulnerability does not require authentication to exploit, increasing its risk. The impact depends on whether outbound SMB connections (port 445) are allowed from the server's network environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict outbound SMB (port 445) connections from the server to untrusted networks to prevent exploitation. Monitor network policies to block unauthorized SMB traffic. Avoid exposing the affected functionality to untrusted users or networks.
Tobit Laboratories AG TeamDavid's Webbox 's move archive functionality (“!ArcEntryMove”) accepts an arbitrary path, which can be set to network… (CVE-2026-54207)
Description
Tobit Laboratories AG TeamDavid's Webbox contains a vulnerability in its move archive functionality (!ArcEntryMove) that accepts arbitrary paths, including network UNC paths. This lack of validation allows unauthenticated attackers to cause the server to initiate outbound SMB connections to attacker-controlled servers. Such connections can lead to exposure of NTLM authentication information, enabling SMB relay or credential theft attacks if outbound SMB traffic is permitted. The issue affects TeamDavid through Rollout 524.
CVSS v4.0
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The move archive functionality (!ArcEntryMove) in Tobit Laboratories AG TeamDavid's Webbox accepts arbitrary path inputs without validation, including UNC network paths (e.g., \\Server\Share). This causes the server to make outbound SMB connection attempts to attacker-controlled endpoints. Because these connections can trigger NTLM authentication, attackers can potentially capture NTLM hashes or perform SMB relay attacks. Exploitation is possible without authentication. The vulnerability is identified as CVE-2026-54207 and affects versions through Rollout 524.
Potential Impact
An attacker can cause the vulnerable server to authenticate to arbitrary SMB servers controlled by the attacker, potentially exposing NTLM authentication credentials such as hashes. This can facilitate SMB relay attacks or credential theft. The vulnerability does not require authentication to exploit, increasing its risk. The impact depends on whether outbound SMB connections (port 445) are allowed from the server's network environment.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict outbound SMB (port 445) connections from the server to untrusted networks to prevent exploitation. Monitor network policies to block unauthorized SMB traffic. Avoid exposing the affected functionality to untrusted users or networks.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-ppvf-phq2-5chq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-54207"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a75f70dbf8831d53984f768
Added to database: 08/07/2026, 15:17:33 UTC
Last enriched: 08/07/2026, 15:31:43 UTC
Last updated: 08/08/2026, 02:40:59 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.