CVE-2026-54200
Received Received - Intake

Local File Inclusion in TeamDavid's Webbox

Vulnerability report for CVE-2026-54200, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: Switzerland Government Common Vulnerability Program

Description

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form fieldΒ 'scjob', files can be attached to a message, which can then be downloaded by an authenticated user. A filter is in place that restricts access to the David con-fig folder and the user folder. However, this filter can be bypassed by specifying an alternate data stream, allowing the download of sensitive files such as other users' access files containing their passwords or the server's private key.Β This issue affects TeamDavid through Rollout 524.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tobit_laboratories_ag teamdavid to 524 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

TeamDavid's Webbox has a local file inclusion vulnerability in the email, fax, or SMS sending feature. By using a special command '@@attach' in the 'scjob' form field, authenticated users can attach and download files. A security filter blocks access to sensitive folders like David config or user folders, but this filter can be bypassed using alternate data streams, allowing access to sensitive files such as passwords or private keys.

Detection Guidance

This vulnerability can be detected by checking for unauthorized file attachments via the 'scjob' form field with '@@attach' commands. Inspect server logs for suspicious file download requests, particularly targeting sensitive paths like the David config folder or user folders. Look for alternate data stream patterns in URLs or form submissions.

Impact Analysis

An attacker with access could exploit this to steal sensitive data like user passwords or server private keys. This could lead to unauthorized access, data breaches, or further attacks on the system. The vulnerability requires authentication but allows lateral movement within the system once exploited.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations using TeamDavid's Webbox may face compliance violations, legal penalties, and reputational damage if exploited.

Mitigation Strategies

Immediately update TeamDavid to the latest version beyond Rollout 524. Disable or restrict access to the 'scjob' form field functionality if not required. Implement strict input validation to block '@@attach' commands and alternate data stream patterns. Review and restrict permissions on sensitive folders like the David config directory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54200. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart