CVE-2026-92371
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TeamViewer | Full Client | 15.0 < 15.82 | affected |
| TeamViewer | Host | 15.0 < 15.82 | affected |
Weaknesses
- CWE-59: CWE-59 Improper link resolution before file access ('link following')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.