CVE-2026-19743
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop Clients
CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th
Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.
| CWE | CWE-22 |
| Vendor | teamviewer |
| Product | full client |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for teamviewer full client
Be the first to know when new high vulnerabilities affecting teamviewer full client are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
TeamViewer / Full Client
15.0 < 15.82 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8) 14.7.0 (Windows) < 14.7.48855 (Windows) 13.2.0 (Windows) < 13.2.36230 (Windows) 14.7.0 (Linux) < 14.7.48855 (Linux) 13.2.0 (Linux) < 13.2.153995 (Linux) 14.7.0 (MacOS) < 14.7.48855 (MacOS) 13.2.0 (MacOS) < 13.2.153994 (MacOS)
TeamViewer / Host
15.0 < 15.82 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8) 14.7.0 (Windows) < 14.7.48855 (Windows) 13.2.0 (Windows) < 13.2.36230 (Windows) 14.7.0 (Linux) < 14.7.48855 (Linux) 13.2.0 (Linux) < 13.2.153995 (Linux) 14.7.0 (MacOS) < 14.7.48855 (MacOS) 13.2.0 (MacOS) < 13.2.153994 (MacOS)
References
Credits
We thank Timo De Clercq & 0x_alibabas (Giuliano Sanfins) for the discovery and responsible disclosure.