CVE-2026-19743 PUBLISHED

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop Clients

Assigner: TV
Reserved: 13.08.2026 Published: 29.09.2026 Updated: 29.09.2026

Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor TeamViewer
Product Full Client
Versions Default: unaffected
  • affected from 15.0 to 15.82 (excl.)
  • affected from 15.64.0 (Legacy Windows 7 & 8) to 15.64.8 (Legacy Windows 7 & 8) (excl.)
  • affected from 14.7.0 (Windows) to 14.7.48855 (Windows) (excl.)
  • affected from 13.2.0 (Windows) to 13.2.36230 (Windows) (excl.)
  • affected from 14.7.0 (Linux) to 14.7.48855 (Linux) (excl.)
  • affected from 13.2.0 (Linux) to 13.2.153995 (Linux) (excl.)
  • affected from 14.7.0 (MacOS) to 14.7.48855 (MacOS) (excl.)
  • affected from 13.2.0 (MacOS) to 13.2.153994 (MacOS) (excl.)
Vendor TeamViewer
Product Host
Versions Default: unaffected
  • affected from 15.0 to 15.82 (excl.)
  • affected from 15.64.0 (Legacy Windows 7 & 8) to 15.64.8 (Legacy Windows 7 & 8) (excl.)
  • affected from 14.7.0 (Windows) to 14.7.48855 (Windows) (excl.)
  • affected from 13.2.0 (Windows) to 13.2.36230 (Windows) (excl.)
  • affected from 14.7.0 (Linux) to 14.7.48855 (Linux) (excl.)
  • affected from 13.2.0 (Linux) to 13.2.153995 (Linux) (excl.)
  • affected from 14.7.0 (MacOS) to 14.7.48855 (MacOS) (excl.)
  • affected from 13.2.0 (MacOS) to 13.2.153994 (MacOS) (excl.)

Solutions

Update to the latest version.

Credits

  • We thank Timo De Clercq & 0x_alibabas (Giuliano Sanfins) for the discovery and responsible disclosure. finder

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE

Impacts

  • CAPEC-126 Path Traversal