CVE-2026-19042

Summary

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking the malicious link.

Affected Software

VendorProductVersion RangeStatus
TeamViewerFull Client15.0 < 15.81.5affected
TeamViewerFull Client14.0 < 14.7.488838affected
TeamViewerFull Client13.0 < 13.2.153978affected
TeamViewerHost15.0 < 15.81.5affected
TeamViewerHost14.0 < 14.7.488838affected
TeamViewerHost13.0 < 13.2.153978affected

Weaknesses

  • CWE-78: CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References