TeamViewer has released security updates to fix five high-severity vulnerabilities affecting its Full Client, Host, and related components across Windows, Linux, and macOS.
The most serious issue could allow attackers to bypass configured remote-session permissions and potentially execute code on vulnerable systems.
The company urged customers to update TeamViewer clients to version 15.82 or the latest version available. TeamViewer said it is not aware of public disclosure or active exploitation of the vulnerabilities in the wild.
The primary privilege-escalation issue, tracked as CVE-2026-19743, affects TeamViewer Full Client and Host installations before version 15.82 on Windows, Linux, and macOS.
The TeamViewer local IPC flaw allows low-privileged authenticated users to manipulate file paths and write arbitrary files with elevated SYSTEM or root privileges.
The flaw has a CVSS score of 7.8. It is classified as CWE-22, an improper limitation of a pathname to a restricted directory, commonly known as path traversal.
The issue also affects several supported legacy and maintenance releases, including TeamViewer 15.64, 14.7, and 13.2 on selected operating systems.
TeamViewer Vulnerabilities
TeamViewer also addressed CVE-2026-92369, a time-of-check time-of-use race condition in the Windows installer rollback mechanism.
A local attacker with low privileges could replace backup files located in a user-writable temporary directory before an elevated installer restores them. If successfully timed during an installation, update, or rollback event, the attack could result in SYSTEM-level privileges.
Another vulnerability, CVE-2026-92371, impacts the Cloud Session Recording function on Linux. The flaw involves improper link resolution during file access.
A local authenticated attacker could exploit a race condition to redirect privileged file operations to unintended locations. This issue affects Linux TeamViewer Full Client and Host versions from 15.0 through releases before 15.82.
CVE-2026-92368 is a heap-based buffer overflow when handling TeamViewer .tvs session recording files on Linux and macOS. The issue stems from a size mismatch during decompression of recorded session data.
An attacker could create a malicious session recording file and trick a victim into opening it through the “Play or convert recorded session” feature.
Successful exploitation could allow arbitrary code execution with the logged-in user’s permissions. The vulnerability affects TeamViewer versions from 15.70 up to, but not including, 15.82 on Linux and macOS.
| CVE ID | Vulnerability | Severity | CVSS |
|---|---|---|---|
| CVE-2026-19743 | Path traversal in local IPC | High | 7.8 |
| CVE-2026-92368 | Heap buffer overflow in .tvs playback | High | 7.8 |
| CVE-2026-92369 | TOCTOU race in Windows installer | High | 7.3 |
| CVE-2026-92370 | Improper access control | High | 8.8 |
| CVE-2026-92371 | Improper link resolution | High | 7.0 |
CVE-2026-92370, the highest-rated flaw with a CVSS score of 8.8, could allow authenticated remote attackers to bypass user-configured restrictions and perform denied actions by altering access-control parameters.
TeamViewer warned that the flaw could lead to unauthorized activity and potentially remote code execution on the affected endpoint.
Organizations should identify systems running TeamViewer Full Client or Host and upgrade to version 15.82 or the latest supported maintenance release.
Security teams should also review TeamViewer access-control settings, limit remote-access privileges, restrict local access to managed endpoints, and monitor for unusual installer activity, suspicious session-recording files, or unexpected changes to protected system files.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
