TV-2026-1009

Command Injection in TeamViewer Clients for Linux through Chat Link Handling

Bulletin ID
TV-2026-1009
Issue Date
26 aug. 2026
Last Update
26 aug. 2026
Priority
Important
CVSS
8.8 (High)
Assigned CVE
CVE-2026-19042
Affected Products
TeamViewer Remote
TeamViewer Tensor
TeamViewer ONE

1. Summary

A vulnerability has been discovered in the TeamViewer Client for Linux which allows Remote Code Execution via Chat.

2. Vulnerability details

CVE-ID

Description

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking the malicious link.

 

Sending a chat message requires the attacker to either be included in the recipient’s contact list or the recipient to have explicitly enabled chat messages from users outside their contact list. By default, this setting is disabled.

 

The vulnerability has been fixed with version 15.81.5 and additional versions listed below. We recommend updating to the latest available version.

 

At the time of publication, we are not aware of any prior public disclosure of this issue or any indication of exploitation in the wild.

CVSS3.1 Score

Base Score 8.8 (High)

CVSS3.1 Vector String

Problem type

3. Affected software and versions

Product
Versions
Info

TeamViewer Full Client (Linux)

< 15.81.5

TeamViewer Host (Linux)

< 15.81.5

Legacy versions
Versions
Info

TeamViewer Full Client V14 (Linux)

< 14.7.48838

TeamViewer Host V14 (Linux)

< 14.7.48838

TeamViewer Full Client V13 (Linux)

< 14.7.48838

TeamViewer Host V13 (Linux)

< 14.7.48838

4. Solutions and mitigations

  • Update to the latest version (15.81.5 or the latest version available) 
  • As a temporary mitigation, if an immediate update is not feasible, users are advised not to click any links received via chat in affected TeamViewer clients. 

5. Acknowledgements

We thank HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL) for the discovery and responsible disclosure via TeamViewer’s Bug Bounty program.