CVE-2026-92371 Details
Description
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.
A vulnerability exists in TeamViewer Full Client and Host for Linux in versions prior to 15.82. It involves improper path validation in the Cloud Session Recording functionality, allowing local authenticated attackers to exploit a race condition. This exploitation can lead to privileged file operations in unintended locations on the affected system.
Users are advised to update to TeamViewer version 15.82 or the latest available version. Instructions for downloading the latest version can be found on the TeamViewer website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/ | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TeamViewer Full Client | < 15.82 < 15.64.8 (semver) < 14.7.48855 (semver) < 13.2.36230 (semver) < 14.7.48855 (semver) < 13.2.153995 (semver) < 14.7.48855 (semver) < 13.2.153994 (semver) |
CPE
Remediation
| |
| TeamViewer Host | < 15.82 < 15.64.8 (semver) < 14.7.48855 (semver) < 13.2.36230 (semver) < 14.7.48855 (semver) < 13.2.153995 (semver) < 14.7.48855 (semver) < 13.2.153994 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion