CVE-2026-12070
Received Received - Intake

Arbitrary File Deletion in TeamDavid's Webbox

Vulnerability report for CVE-2026-12070, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: Switzerland Government Common Vulnerability Program

Description

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any file on the system can be deleted.Β This issue affects TeamDavid through Rollout 524.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tobit_laboratories_ag teamdavid to 524 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker to delete any file on the system by exploiting the email, fax, or SMS functionality in Tobit Laboratories AG TeamDavid's Webbox. The attacker can specify an @@COMMENTFILE command in the scjob form field to trigger arbitrary file deletion. This affects TeamDavid versions up to Rollout 524.

Detection Guidance

To detect this vulnerability, monitor for unusual file deletion activities or suspicious commands containing @@COMMENTFILE in the scjob form field. Check TeamDavid logs for unauthorized access attempts to the send email, fax, or SMS functionality. Review system logs for unexpected file deletions or errors related to TeamDavid processes.

Impact Analysis

An attacker could delete critical system files, leading to data loss, system instability, or denial of service. If sensitive files are deleted, it could disrupt business operations or expose confidential information. The CVSS score of 8.4 indicates high severity with potential for significant impact.

Compliance Impact

This vulnerability could lead to unauthorized file deletion, potentially violating data integrity and availability requirements under GDPR and HIPAA. Loss of sensitive data may result in non-compliance, legal penalties, or reputational damage for organizations handling regulated information.

Mitigation Strategies

Immediately update TeamDavid to the latest version beyond Rollout 524. Disable or restrict access to the send email, fax, or SMS functionality if not required. Implement network segmentation to limit exposure. Monitor for any signs of exploitation and review logs for unauthorized activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12070. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart