CVE-2026-12070
Tobit Laboratories AG · TeamDavid
Tobit Laboratories AG TeamDavid Webbox contains an arbitrary file deletion vulnerability within the email, fax, and SMS transmission functions.
Executive summary
An authenticated arbitrary file deletion vulnerability in Tobit Laboratories AG TeamDavid allows attackers to delete critical files, leading to potential service disruption.
Vulnerability
This vulnerability is caused by insecure handling of file path inputs, which allows an authenticated attacker with low privileges to target arbitrary files on the host filesystem for deletion. The issue is located within the Webbox component, specifically affecting the message transmission modules.
Business impact
Successful exploitation of this vulnerability could lead to significant system instability or denial of service by deleting critical configuration or application files. With a CVSS score of 8.4, this represents a major availability risk, as the deletion of essential files can render the TeamDavid application or the underlying server inoperable.
Remediation
Immediate Action: Update the Tobit Laboratories AG TeamDavid software to a version beyond Rollout 524 as specified in the vendor release notes.
Proactive Monitoring: Review file system integrity and monitor server logs for unauthorized deletion requests or unusual application behavior following file operations.
Compensating Controls: Ensure that the service account running the TeamDavid application operates with the principle of least privilege, specifically restricting write and delete access to system directories outside of the application scope.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The risk of service disruption via arbitrary file deletion necessitates prompt remediation. Administrators should ensure the software is updated to the latest release to close this security gap and prevent potential malicious file removal.