Link following in TeamViewer products - CVE-2026-92371
Published: September 29, 2026
Vulnerability details
The vulnerability allows a local user to perform privileged file operations in unintended locations.
The vulnerability exists due to improper link resolution before file access in the Cloud Session Recording functionality when validating file paths and subsequently accessing files. A local user can exploit a race condition during path validation and file access to perform privileged file operations in unintended locations.
Affected software
TeamViewer Host for macOS
TeamViewer Full Client for macOS
TeamViewer Full Client for Linux
TeamViewer Host for Linux
TeamViewer Remote Host for Windows
How to mitigate CVE-2026-92371
TeamViewer Remote Host for Windows - addressed in versions 13.2.36230, 14.7.48855, 15.64.8, 15.82
TeamViewer Host for macOS - addressed in versions 13.2.153994, 14.7.48855, 15.82
TeamViewer Full Client for macOS - addressed in versions 13.2.153994, 14.7.48855, 15.82
TeamViewer Full Client for Linux - addressed in versions 13.2.153995, 14.7.48855, 15.82
TeamViewer Host for Linux - addressed in versions 13.2.153995, 14.7.48855, 15.82