CVE-2026-12070: TeamDavid: Arbitrary File Deletion via form field 'scjob'
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any file on the system can be deleted. This issue affects TeamDavid through Rollout 524.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12070?
The severity of CVE-2026-12070 is rated at 65, indicating a medium risk.
How do I fix CVE-2026-12070?
To fix CVE-2026-12070, update TeamDavid's Webbox to the latest version following Rollout 524.
What is CVE-2026-12070 about?
CVE-2026-12070 relates to an arbitrary file deletion vulnerability in TeamDavid's Webbox caused by a risky form field input.
Which versions of TeamDavid are affected by CVE-2026-12070?
CVE-2026-12070 affects TeamDavid's Webbox through Rollout 524.
What can attackers do with CVE-2026-12070?
With CVE-2026-12070, attackers can delete files on the system by manipulating the 'scjob' form field.