CVE-2026-92371

Summary

TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.

Affected Software

VendorProductVersion RangeStatus
TeamViewerFull Client15.0 < 15.82affected
TeamViewerHost15.0 < 15.82affected

Weaknesses

  • CWE-59: CWE-59 Improper link resolution before file access ('link following')

References