VYPR
patchPublished Oct 1, 2026· 1 source

Critical TeamViewer Vulnerabilities Enable Code Execution Attacks Via Remote Session

TeamViewer has released updates to address five high-severity vulnerabilities, including a path traversal flaw that could allow attackers to execute code on vulnerable systems.

TeamViewer has issued urgent security updates to patch five high-severity vulnerabilities affecting its remote access software across Windows, Linux, and macOS. The most critical of these flaws, CVE-2026-19743, is a path traversal vulnerability that could enable attackers to bypass security permissions and execute arbitrary code on compromised systems.

The path traversal vulnerability (CVE-2026-19743) affects TeamViewer Full Client and Host installations prior to version 15.82. It allows low-privileged authenticated users to manipulate file paths, enabling them to write arbitrary files with elevated SYSTEM or root privileges. This flaw, rated with a CVSS score of 7.8, is categorized as CWE-22, indicating an improper limitation of a pathname to a restricted directory.

In addition to the path traversal issue, TeamViewer has also addressed a time-of-check to time-of-use (TOCTOU) race condition in its Windows installer rollback mechanism (CVE-2026-92369). A local attacker with minimal privileges could exploit this by replacing backup files in a temporary directory before the installer restores them, potentially leading to SYSTEM-level privileges during installation or update processes.

Further vulnerabilities include CVE-2026-92371, an improper link resolution flaw in the Cloud Session Recording function on Linux. This could allow a local authenticated attacker to redirect privileged file operations to unintended locations. On Linux and macOS, a heap-based buffer overflow (CVE-2026-92368) exists when handling .tvs session recording files, stemming from a size mismatch during decompression, which could lead to arbitrary code execution if a victim opens a malicious recording file.

The highest-rated vulnerability, CVE-2026-92370, carries a CVSS score of 8.8 and involves improper access control. This flaw could permit authenticated remote attackers to bypass user-configured restrictions and perform unauthorized actions by manipulating access-control parameters, potentially leading to remote code execution.

TeamViewer stated that it is not aware of any public disclosure or active exploitation of these vulnerabilities in the wild. However, the company strongly advises all users to update their TeamViewer clients to version 15.82 or the latest available version to mitigate these risks.

Organizations using TeamViewer are urged to identify all affected installations and apply the necessary updates promptly. Security teams should also review their TeamViewer access control configurations, limit remote access privileges, restrict local access to endpoints, and monitor for any unusual installer activity, suspicious session recording files, or unexpected modifications to system files.

Synthesized by Vypr AI
Critical TeamViewer Vulnerabilities Enable Code Execution Attacks Via Remote Session · VYPR