Description
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.
Published: 2026-09-29
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

TeamViewer Full Client and Host for Linux contain a race condition in the Cloud Session Recording feature that leads to improper path validation. An attacker who is already authenticated locally can trigger this race condition and cause privileged file operations in locations that are not intended by the application. This flaw allows the attacker to create, modify, or delete arbitrary files with elevated privileges, exposing the system to data tampering, persistence, or damage to critical directories.

Affected Systems

The vulnerability affects TeamViewer Full Client and Host on Linux versions earlier than 15.82. Systems running these products are susceptible unless updated to the latest release from TeamViewer.

Risk and Exploitability

The CVSS score of 7 indicates a high severity for potential privilege escalation. While the EPSS score is not available, the lack of listing in the CISA KEV catalog suggests no known public exploitation yet. The likely attack vector is a local authenticated user who can manipulate the Cloud Session Recording function, and exploitation requires taking advantage of the race condition during path validation. Without patching, the flaw can enable local attackers to perform privileged file operations across the system.

Generated by OpenCVE AI on September 30, 2026 at 00:56 UTC.

Remediation

Vendor Solution

Update to the latest version.


OpenCVE Recommended Actions

  • Update TeamViewer Full Client and Host to the latest version (15.82 or newer).
  • Remove or secure any custom Cloud Session Recording configuration directories to prevent arbitrary path specification.
  • If update cannot be applied immediately, confine TeamViewer processes in a restricted environment, such as a container or chroot, to limit filesystem exposure.

Generated by OpenCVE AI on September 30, 2026 at 00:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Teamviewer
Teamviewer full Client
Teamviewer host
Vendors & Products Teamviewer
Teamviewer full Client
Teamviewer host

Tue, 29 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.
Title Local Privilege Escalation via Improper Link Resolution in Cloud Session Recording
Weaknesses CWE-59
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Teamviewer Full Client Host
cve-icon MITRE

Status: PUBLISHED

Assigner: TV

Published:

Updated: 2026-09-29T15:41:12.493Z

Reserved: 2026-09-16T07:16:01.956Z

Link: CVE-2026-92371

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-29T16:17:15.177

Modified: 2026-09-29T21:35:31.350

Link: CVE-2026-92371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T01:00:09Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')