Link following in TeamViewer products - CVE-2026-92371

 

Link following in TeamViewer products - CVE-2026-92371

Published: September 29, 2026


Vulnerability identifier: #VU152873
CSH Severity: Low
CVSS v4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-92371
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform privileged file operations in unintended locations.

The vulnerability exists due to improper link resolution before file access in the Cloud Session Recording functionality when validating file paths and subsequently accessing files. A local user can exploit a race condition during path validation and file access to perform privileged file operations in unintended locations.


Affected software

TeamViewer Remote Full Client for Windows
TeamViewer Host for macOS
TeamViewer Full Client for macOS
TeamViewer Full Client for Linux
TeamViewer Host for Linux
TeamViewer Remote Host for Windows

How to mitigate CVE-2026-92371

Install security update from vendor's website.

TeamViewer Remote Full Client for Windows - addressed in versions 13.2.36230, 14.7.48855, 15.64.8, 15.82
TeamViewer Remote Host for Windows - addressed in versions 13.2.36230, 14.7.48855, 15.64.8, 15.82
TeamViewer Host for macOS - addressed in versions 13.2.153994, 14.7.48855, 15.82
TeamViewer Full Client for macOS - addressed in versions 13.2.153994, 14.7.48855, 15.82
TeamViewer Full Client for Linux - addressed in versions 13.2.153995, 14.7.48855, 15.82
TeamViewer Host for Linux - addressed in versions 13.2.153995, 14.7.48855, 15.82

External References

Related Security Bulletins