CVE Feed

    Dashboard / CVE / CVE-2026-12070

    CVE-2026-12070

    Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any file on the system can be deleted. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.

    Published:Aug 7, 2026
    Last Modified:Sep 7, 2026
    EPS:Aug 7, 2026
    EPSS Score:0.00235
    CVSS Score:8.4

    Affected Products

    Vendor
    Tobit Laboratories Ag
    Product
    Teamdavid

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High