CVE-2026-4391 Details
Description
A security vulnerability has been detected in TeamSpeak 3 Server up to 3.13.7. This vulnerability affects unknown code of the component ECC Key Parser. Such manipulation leads to heap-based buffer overflow. The attack may be launched remotely. Upgrading to version 3.13.8 is able to resolve this issue. It is suggested to upgrade the affected component.
A heap-based buffer overflow vulnerability has been identified in TeamSpeak 3 Server versions prior to 3.13.8. This issue arises in the ECC Key Parser component, where improper handling of key data can be exploited to overwrite memory. The vulnerability can be triggered remotely, leading to potential denial-of-service conditions.
Users are advised to upgrade to TeamSpeak 3 Server version 3.13.8, available for download on the TeamSpeak website. Instructions for downloading the updated version can be found in the TeamSpeak Security Advisory TS-SA-2026-001.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 27, 2026CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://files.teamspeak-services.com/docs/security/TS-SA-2026-001.html | [email protected] | AdvisoryBundleRemedyVendor |
| https://modzero.com/en/advisories/mz-26-01-teamspeak/ | [email protected] | AdvisoryBundleExploitRemedy |
| https://vuldb.com/vuln/366315 | [email protected] | Content Wall |
| https://vuldb.com/vuln/366315/cti | [email protected] | Content Wall |
| https://www.teamspeak.com/en/downloads/#server | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TeamSpeak | <= 3.13.7 (semver) |
CPE
Remediation
| |
| TeamSpeak SDK | <= 3.3.1 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | New CVE Received | [email protected] |
Volerion