CVE-2026-12070
TeamDavid: Arbitrary File Deletion via form field 'scjob'
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any file on the system can be deleted.Β This issue affects TeamDavid through Rollout 524.
| CWE | CWE-73 |
| Vendor | tobit laboratories ag |
| Product | teamdavid |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for tobit laboratories ag teamdavid
Be the first to know when new unknown vulnerabilities affecting tobit laboratories ag teamdavid are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
Tobit Laboratories AG / TeamDavid
0 β€ Rollout 524
References
Credits
Dario Weiss of InfoGuard Labs