Description
Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.
Published: 2026-09-29
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from improper validation of file paths in the local IPC service of TeamViewer Full Client and Host. An attacker with low‑privilege local access can craft IPC commands that manipulate pathname traversal, enabling writes of arbitrary files with elevated privileges such as NT AUTHORITY/SYSTEM on Windows or root on Linux and macOS. Exploiting this flaw permits a local user to overwrite critical binaries, configuration files, or inject executable content, thereby elevating their permissions to system level. The weakness is defined as a Classic Path Traversal (CWE-22).

Affected Systems

Affected are the TeamViewer Full Client and TeamViewer Host running on Windows, Linux, and macOS. Versions older than 15.82 are vulnerable; all builds prior to this release expose the IPC service to local users who can supply crafted commands.

Risk and Exploitability

The vulnerability scores 7.8 on the CVSS scale, indicating a high severity level, though no EPSS value is reported and it is not listed in the CISA KEV catalog. The attack is local; an authenticated user with ordinary privileges can trigger the exploit via the IPC interface. Because it requires local access and relies on IPC, remote exploitation is unlikely. Nonetheless, the potential impact of achieving SYSTEM or root warrants prompt remediation.

Generated by OpenCVE AI on September 30, 2026 at 01:08 UTC.

Remediation

Vendor Solution

Update to the latest version.


OpenCVE Recommended Actions

  • Update to the latest version of TeamViewer Full Client and Host (≥ 15.82).
  • Restrict local IPC service access to trusted users to reduce the attack surface.
  • Monitor the system for unauthorized file writes or changes to critical files and investigate any anomalies promptly.

Generated by OpenCVE AI on September 30, 2026 at 01:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Teamviewer
Teamviewer full Client
Teamviewer host
Vendors & Products Teamviewer
Teamviewer full Client
Teamviewer host

Tue, 29 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.
Title Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop Clients
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Teamviewer Full Client Host
cve-icon MITRE

Status: PUBLISHED

Assigner: TV

Published:

Updated: 2026-09-29T15:39:11.503Z

Reserved: 2026-08-13T13:55:15.000Z

Link: CVE-2026-19743

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-29T16:17:07.177

Modified: 2026-09-29T21:35:31.350

Link: CVE-2026-19743

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T01:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')