Description
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in
the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message,
which can then be downloaded by an authenticated user. A filter is in
place that restricts access to the David con-fig folder and the user
folder. However, this filter can be bypassed by specifying an alternate
data stream, allowing the download of sensitive files such as other
users' access files containing their passwords or the server's private
key. This issue affects TeamDavid before Rollout 528.

Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
Published: 2026-08-07
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Local file inclusion enabling unauthorized download of sensitive files
Action: Immediate Patch
AI Analysis

Impact

Tobit Laboratories AG TeamDavid's Webbox component contains a local file inclusion flaw triggered by the "scjob" form field. By specifying an "@@attach" command, an authenticated user can override the intended file path and supply an alternate data stream, allowing the server to bypass its file‑path restrictions. This bypass enables the download of arbitrary files, including other users' credential files and the server's private key, thereby exposing confidential information.

Affected Systems

The flaw applies to all TeamDavid releases before Rollout 528, which were released prior to June 30, 2026. Users of Tobit Laboratories AG’s TeamDavid are vulnerable through the Webbox send‑email/fax/SMS interface. Starting with Rollout 528, the affected functionality is disabled by default, removing this exposure for newer releases.

Risk and Exploitability

The CVSS base score of 8.4 classifies this vulnerability as High severity. The attack requires an authenticated user, and the description indicates that it is likely a user with messaging privileges who submits a crafted "scjob" value containing "@@attach", causing the server to serve the requested file. The EPSS score is < 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ability to download any file the attacker selects represents a significant risk for impacted installations.

Generated by OpenCVE AI on September 7, 2026 at 15:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TeamDavid to a version released after Rollout 528 where the "@@attach" feature is removed or secured.
  • If an update is not immediately possible, reconfigure the application to strip the "@@attach" directive from the "scjob" field, allowing only regular filenames and rejecting any alternate data stream syntax.
  • Restrict the Webbox messaging interface to privileged users only, or disable the attachment capability for non‑admin accounts, and monitor for anomalous download activity.
  • Deploy an application‑level firewall rule or WAF to block requests containing "@@attach" or other special stream prefixes and enforce path sanitization.

Generated by OpenCVE AI on September 7, 2026 at 15:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message, which can then be downloaded by an authenticated user. A filter is in place that restricts access to the David con-fig folder and the user folder. However, this filter can be bypassed by specifying an alternate data stream, allowing the download of sensitive files such as other users' access files containing their passwords or the server's private key. This issue affects TeamDavid through Rollout 524. Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message, which can then be downloaded by an authenticated user. A filter is in place that restricts access to the David con-fig folder and the user folder. However, this filter can be bypassed by specifying an alternate data stream, allowing the download of sensitive files such as other users' access files containing their passwords or the server's private key. This issue affects TeamDavid before Rollout 528. Starting with Rollout 528 (June 30, 2026), the affected functionality is disabled by default and the vulnerabilities are therefore no longer exposed through this functionality.
References

Mon, 10 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 08 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid
Vendors & Products Tobit Laboratories Ag
Tobit Laboratories Ag teamdavid

Fri, 07 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message, which can then be downloaded by an authenticated user. A filter is in place that restricts access to the David con-fig folder and the user folder. However, this filter can be bypassed by specifying an alternate data stream, allowing the download of sensitive files such as other users' access files containing their passwords or the server's private key. This issue affects TeamDavid through Rollout 524.
Title TeamDavid: Local File Inclusion via the form field 'scjob'
Weaknesses CWE-73
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:H/SI:N/SA:L'}


Subscriptions

Tobit Laboratories Ag Teamdavid
cve-icon MITRE

Status: PUBLISHED

Assigner: NCSC.ch

Published:

Updated: 2026-09-07T12:44:25.997Z

Reserved: 2026-06-12T09:32:44.531Z

Link: CVE-2026-54200

cve-icon Vulnrichment

Updated: 2026-08-10T11:29:20.343Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T10:16:56.640

Modified: 2026-09-07T13:20:24.897

Link: CVE-2026-54200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T16:00:13Z

Weaknesses
  • CWE-73

    External Control of File Name or Path