AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-54200

HIGH · CVSS 8.4 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion flaw that allows authenticated users to bypass existing filters and download sensitive files, including other users' access files and the server's private key, by manipulating the '@@attach' command in the 'scjob' form field. This high-severity vulnerability poses a significant risk to user data confidentiality and server integrity. Organizations using TeamDavid versions up to Rollout 524 should prioritize remediation to protect against potential data breaches.

CVE
CVE-2026-54200
Severity
HIGH
CVSS
8.4
EPSS
0.24%

Original NVD Description

Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a local file inclusion vulnerability in the send email, fax, SMS, etc. functionality. By specifying an '@@attach' command in the form field 'scjob', files can be attached to a message, which can then be downloaded by an authenticated user. A filter is in place that restricts access to the David con-fig folder and the user folder. However, this filter can be bypassed by specifying an alternate data stream, allowing the download of sensitive files such as other users' access files containing their passwords or the server's private key. This issue affects TeamDavid through Rollout 524.