CVE-2026-16444
Improper Validation of File Paths in TeamViewer Desktop Clients
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user.
| CWE | CWE-73 |
| Vendor | teamviewer |
| Product | full client, host, quicksupport & portable |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for teamviewer full client, host, quicksupport & portable
Be the first to know when new high vulnerabilities affecting teamviewer full client, host, quicksupport & portable are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
TeamViewer / Full Client, Host, QuickSupport & Portable
15.0 < 15.81.5
TeamViewer / Full Client, Host, QuickSupport & Portable (for Windows 7 & 8)
15.64.0 < 15.64.7
TeamViewer / Full Client, Host, QuickSupport (v14 for Windows)
14.0 < 14.7.48833
TeamViewer / Full Client, Host, QuickSupport (v14 for Linux)
14.0 < 14.7.48838
TeamViewer / Full Client, Host, QuickSupport (v14 for macOS)
14.0 < 14.7.48838
TeamViewer / Full Client, Host, QuickSupport & Portable (v13 for Windows)
13.0 < 13.2.36229
TeamViewer / Full Client, Host, QuickSupport (v13 for Linux)
13.0 < 13.2.153978
TeamViewer / Full Client, Host, QuickSupport (v13 for macOS)
13.0 < 13.2.153981
References
Credits
Jamir0quai & sam91281