CVE-2026-19042: TeamViewer Full Client

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking the malicious link.

Affected products

  • TeamViewer Full Client: from 15.0, before 15.81.5 (fixed in 15.81.5); from 14.0, before 14.7.488838 (fixed in 14.7.488838); from 13.0, before 13.2.153978 (fixed in 13.2.153978)
  • TeamViewer Host: from 15.0, before 15.81.5 (fixed in 15.81.5); from 14.0, before 14.7.488838 (fixed in 14.7.488838); from 13.0, before 13.2.153978 (fixed in 13.2.153978)

Published 2026-08-26. Last modified 2026-09-01.