What is CVE-2026-54200?
A Local File Inclusion vulnerability exists in Tobit Laboratories AG TeamDavid's Webbox, specifically in the send email, fax, and SMS functionality where the '@@attach' command in the 'scjob' field allows an authenticated user to attach and download local files, potentially leading to data exposure. Users are advised to apply the necessary security patch provided by the vendor immediately.
Azərbaycanca: Tobit Laboratories AG TeamDavid's Webbox proqramında e-poçt, faks və SMS göndərmə funksionallığında "scjob" sahəsi vasitəsilə '@@attach' əmri ilə autentifikasiya olunmuş istifadəçinin lokal faylları daxil edib oxumasına imkan verən Local File Inclusion zəifliyi aşkarlanıb. Bu, həssas məlumatların sızmasına səbəb ola bilər. İstifadəçilərə təcili olaraq təchizatçı tərəfindən təqdim edilən təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Tobit Laboratories AG
FAQ2
In which functionality of Tobit Laboratories AG TeamDavid's Webbox was CVE-2026-54200 discovered?
The CVE-2026-54200 vulnerability was discovered specifically in the send email, fax, and SMS functionality.
Which command in the 'scjob' field can an authenticated user exploit in CVE-2026-54200?
An authenticated user can exploit the '@@attach' command in the 'scjob' field to include local files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.