TV-2026-1010

Security Update for Multiple Vulnerabilities in TeamViewer Clients and Related Services

Bulletin ID
TV-2026-1010
Issue Date
29 de set de 2026
Last Update
29 de set de 2026
Priority
Important
CVSS
Up to 8.8 (High)
Assigned CVE
CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, CVE-2026-92371
Affected Products
TeamViewer Remote
TeamViewer Tensor
TeamViewer ONE

1. Summary

TeamViewer has released security updates addressing multiple vulnerabilities affecting TeamViewer Full Client and Host and related services. These vulnerabilities have been resolved in the latest available versions.

TeamViewer strongly recommends that all users update to the latest available version as soon as possible.

2. Vulnerability details

I. Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop Clients 

CVE-ID

Description

Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.

CVSS3.1 Score

Base Score 7.8 (High)

CVSS3.1 Vector String

Problem type

Affected versions

TeamViewer Full Client and Host

  • Prior V15.82 (Windows, MacOS, Linux)
  • Legacy/Maintenance: V15.64 (Windows), V14.7 (Windows, Linux), V13.2 (Windows, Linux)

II. Heap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to Remote Code Execution 

CVE-ID

Description

TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user 

CVSS3.1 Score

Base Score 7.8 (High)

CVSS3.1 Vector String

Problem type

Affected versions

TeamViewer Full Client and Host

  • From V15.70 prior V15.82 (Linux, MacOS)

III. Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer Windows Installer Rollback Mechanism Leads to Local Privilege Escalation

CVE-ID

Description

TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.

CVSS3.1 Score

Base Score 7.3 (High)

CVSS3.1 Vector String

Problem type

Affected versions

TeamViewer Full Client and Host

  • Prior V15.82 (Windows)

  • Legacy/Maintenance: V15.64 (Windows), V14.7 (Windows), V13.2 (Windows)

IV. Remote Session Access Control Bypass Leading to Remote Code Execution

CVE-ID

Description

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.

CVSS3.1 Score

Base Score 8.8 (High)

CVSS3.1 Vector String

Problem type

Affected versions

TeamViewer Full Client and Host

  • Prior V15.82 (Windows, Linux, MacOS)

  • Legacy/Maintenance: V15.64 (Windows), V14.7 (Windows, Linux, MacOS), V13.2 (Windows, Linux, MacOS)

V. Local Privilege Escalation via Improper Link Resolution in Cloud Session Recording

CVE-ID

Description

TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.

CVSS3.1 Score

Base Score 7.0 (High)

CVSS3.1 Vector String

Problem type

Affected versions

TeamViewer Full Client and Host

  • From V15.0 prior V15.82 (Linux)

These vulnerabilities have been resolved in TeamViewer Clients version 15.82 as well as supported maintenance and legacy releases listed below.

TeamViewer is not aware of any public disclosure or active exploitation in the wild. 

3. Affected software and versions

Product
Versions
Info

TeamViewer Full Client (Windows)

< 15.82

TeamViewer Full Client (Linux)

< 15.82

TeamViewer Full Client (MacOS)

< 15.82

TeamViewer Host (Windows)

< 15.82

TeamViewer Host (Linux)

< 15.82

TeamViewer Host (MacOS)

< 15.82

Legacy versions
Versions
Info

Teamviewer Full Client v15.64 (Windows 7 & 8)

< 15.64.8

TeamViewer Full Client v14.7 (Windows)

< 14.7.48855

TeamViewer Full Client v13.2 (Windows)

< 13.2.36230

TeamViewer Full Client v14.7 (Linux)

< 14.7.48855

TeamViewer Full Client v13.2 (Linux)

< 13.2.153995

TeamViewer Full Client v14.7 (MacOS)

< 14.7.48855

TeamViewer Full Client v13.2 (MacOS)

< 13.2.153994

Teamviewer Host v15.64 (Windows 7 & 8)

< 15.64.8

TeamViewer Host v14.7 (Windows)

< 14.7.48855

TeamViewer Host v13.2 (Windows)

< 13.2.36230

TeamViewer Host v14.7 (Linux)

< 14.7.48855

TeamViewer Host v13.2 (Linux)

< 13.2.153995

TeamViewer Host v14.7 (MacOS)

< 14.7.48855

TeamViewer Host v13.2 (MacOS)

< 13.2.153994

4. Solutions and mitigations

  • Update to the latest version (15.82 or the latest version available) 

5. Acknowledgements

TeamViewer would like to thank the security researchers who responsibly reported these issues and worked with us throughout the coordinated vulnerability disclosure process.