CVE-2026-19743 Details
Description
Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.
A vulnerability exists in the local Inter-Process Communication (IPC) service of TeamViewer Full Client and Host on Windows, Linux, and macOS, affecting versions prior to 15.82. This vulnerability allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM or root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, resulting in local privilege escalation.
Users are advised to update to TeamViewer version 15.82 or the latest available version. Instructions for downloading the latest version can be found on the TeamViewer website. For users on legacy versions, TeamViewer Full Client and Host versions 15.64, 14.7, and 13.2 are also available.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/ | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TeamViewer Full Client | < 15.82 15.64 < 15.64.8 (semver) 14.7 < 14.7.48855 (semver) 13.2 < 13.2.36230 (semver) |
CPE
Remediation
| |
| TeamViewer Host | < 15.82 15.64 < 15.64.8 (semver) 14.7 < 14.7.48855 (semver) 13.2 < 13.2.36230 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion