CVE-2026-12070
Last modified
CVE-2026-12070 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to an arbitrary file deletion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an @@COMMENTFILE command in the form field scjob, any file on the system can be deleted. This issue affects TeamDavid through Rollout 524.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Tobit Laboratories AG | TeamDavid | <= Rollout 524 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-12070?
How severe is CVE-2026-12070?
How do I fix CVE-2026-12070?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12060Heptabase developed by Hepta Platforms has a Exposed Dangero…6.9
- CVE-2026-12064When a user invokes curl using a schemeless URL combined wit…7.5
- CVE-2026-12065A vulnerability was identified in Groww Stock, Mutual Fund, …1.8
- CVE-2026-12066A security flaw has been discovered in PbootCMS up to 3.2.12…7.3
- CVE-2026-12068Information disclosure vulnerability in Avira Password Manag…7.4
- CVE-2026-1207An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.…5.4
- CVE-2026-12071The Webbox of TeamDavid by Tobit Laboratories AG constructs …5.3
- CVE-2026-12073The ProfileGrid – User Profiles, Groups and Communities plug…9.8
- CVE-2026-12076Raytha CMS is vulnerable to SQL Injection within the OData f…9.3
- CVE-2026-12077The Dokan Pro plugin for WordPress is vulnerable to time-bas…7.5
- CVE-2026-12079The Dokan Pro plugin for WordPress is vulnerable to time-bas…6.5
- CVE-2026-1208The Friendly Functions for Welcart plugin for WordPress is v…4.3
Are you affected by CVE-2026-12070?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
