Path traversal in TeamViewer products - CVE-2026-19743

 

Path traversal in TeamViewer products - CVE-2026-19743

Published: September 29, 2026


Vulnerability identifier: #VU152869
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-19743
CWE-ID: CWE-22
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper path validation in the local IPC service when processing crafted IPC commands. A local user can send crafted IPC commands that manipulate file paths to escalate privileges.


Affected software

TeamViewer Remote Full Client for Windows
TeamViewer Host for macOS
TeamViewer Full Client for macOS
TeamViewer Full Client for Linux
TeamViewer Host for Linux
TeamViewer Remote Host for Windows

How to mitigate CVE-2026-19743

Install security update from vendor's website.

TeamViewer Remote Full Client for Windows - addressed in versions 13.2.36230, 14.7.48855, 15.64.8, 15.82
TeamViewer Remote Host for Windows - addressed in versions 13.2.36230, 14.7.48855, 15.64.8, 15.82
TeamViewer Host for macOS - addressed in versions 13.2.153994, 14.7.48855, 15.82
TeamViewer Full Client for macOS - addressed in versions 13.2.153994, 14.7.48855, 15.82
TeamViewer Full Client for Linux - addressed in versions 13.2.153995, 14.7.48855, 15.82
TeamViewer Host for Linux - addressed in versions 13.2.153995, 14.7.48855, 15.82

External References

Related Security Bulletins