CVE-2026-92371 PUBLISHED

Local Privilege Escalation via Improper Link Resolution in Cloud Session Recording

Assigner: TV
Reserved: 16.09.2026 Published: 29.09.2026 Updated: 29.09.2026

TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7

Product Status

Vendor TeamViewer
Product Full Client
Versions Default: unaffected
  • affected from 15.0 to 15.82 (excl.)
Vendor TeamViewer
Product Host
Versions Default: unaffected
  • affected from 15.0 to 15.82 (excl.)

Solutions

Update to the latest version.

Credits

  • We thank Romain Igounet and Hugo Leclercq for the discovery and responsible disclosure. finder

References

Problem Types

  • CWE-59 Improper link resolution before file access ('link following') CWE

Impacts

  • CAPEC-27 Leveraging Race Conditions via Symbolic Links