Description
Improper
neutralization of path traversal sequences in TeamViewer Desktop Clients prior
Version 15.81.5 allows an authenticated remote session participant to write files
to unintended locations on the local file system via file transfer or virtual
file clipboard mechanisms. An attacker can leverage this behavior to achieve
arbitrary file write and potentially execute code with the privileges of the
affected user.
Published: 2026-08-26
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated participant in a remote TeamViewer session can write files to arbitrary locations on the local file system by exploiting improper neutralization of path traversal sequences in file transfer or virtual file clipboard operations. The flaw allows the attacker to create or overwrite files with the privileges of the affected user, potentially leading to execution of malicious code. This vulnerability is an instance of path traversal (CWE‑73).

Affected Systems

TeamViewer Desktop Clients - Full Client, Host, QuickSupport, and Portable - running on Windows 7 or Windows 8, and on newer Windows builds bundled with v13 or v14; Linux clients built with v13 or v14; macOS clients built with v13 or v14 - all versions prior to 15.81.5 are affected.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.5, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that the overall exploitation likelihood may be moderate but not negligible. Attackers require authenticated remote session access and can exploit the flaw through standard file transfer or virtual clipboard features, meaning that any user who allows a remote participant can be impacted. The risk is amplified in environments where file system permissions are lax or where the client is granted broad access rights. Given the high severity score and the ability to write arbitrary files, organizations should treat this as a significant security concern until mitigated.

Generated by OpenCVE AI on August 26, 2026 at 10:51 UTC.

Remediation

Vendor Solution

Update to the last available client version.


OpenCVE Recommended Actions

  • Update all TeamViewer Desktop Clients to the latest available version, which includes the fix for the path traversal issue.
  • Restrict remote session invitations to trusted participants only and review sharing settings to limit who may connect.
  • Disable file transfer and virtual clipboard features in the client configuration for sessions where these functions are not needed.

Generated by OpenCVE AI on August 26, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user.
Title Improper Validation of File Paths in TeamViewer Desktop Clients
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TV

Published:

Updated: 2026-08-26T13:36:03.862Z

Reserved: 2026-07-21T07:42:28.976Z

Link: CVE-2026-16444

cve-icon Vulnrichment

Updated: 2026-08-26T13:35:57.752Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T11:00:05Z

Weaknesses
  • CWE-73

    External Control of File Name or Path