What is CVE-2026-12070?
An arbitrary file deletion vulnerability exists in Tobit Laboratories AG's TeamDavid Webbox product. Attackers can delete any file on the system by using the '@@COMMENTFILE' command in the scjob field within the send email, fax, or SMS functionality. This issue affects TeamDavid through Rollout versions, and immediate patching is advised.
Azərbaycanca: Tobit Laboratories AG şirkətinin TeamDavid Webbox məhsulunda ixtiyari fayl silmə zəifliyi aşkarlanıb. Zərərli şəxs e-poçt, faks, SMS göndərmə funksiyalarında scjob sahəsində '@@COMMENTFILE' əmrindən istifadə edərək sistemdəki istənilən faylı silə bilər. Bu kritik boşluq TeamDavid-in Rollout versiyasına qədər təsir edir, dərhal yamaq tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Tobit Laboratories AG
FAQ2
Through which functionality can an attacker delete files in TeamDavid Webbox?
An attacker can delete arbitrary files by using the '@@COMMENTFILE' command in the scjob field within the send email, fax, or SMS functionality.
Up to which version does CVE-2026-12070 affect?
This vulnerability affects TeamDavid through Rollout versions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.