CVE-2026-19743: TeamViewer Full Client

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.

Affected products

  • TeamViewer Full Client: from 15.0, before 15.82 (fixed in 15.82); from 14.7.0 (Windows), before 14.7.48855 (Windows) (fixed in 14.7.48855 (Windows)); from 13.2.0 (Windows), before 13.2.36230 (Windows) (fixed in 13.2.36230 (Windows)); from 14.7.0 (Linux), before 14.7.48855 (Linux) (fixed in 14.7.48855 (Linux)); from 13.2.0 (Linux), before 13.2.153995 (Linux) (fixed in 13.2.153995 (Linux)); from 14.7.0 (MacOS), before 14.7.48855 (MacOS) (fixed in 14.7.48855 (MacOS)); …
  • TeamViewer Host: from 15.0, before 15.82 (fixed in 15.82); from 14.7.0 (Windows), before 14.7.48855 (Windows) (fixed in 14.7.48855 (Windows)); from 13.2.0 (Windows), before 13.2.36230 (Windows) (fixed in 13.2.36230 (Windows)); from 14.7.0 (Linux), before 14.7.48855 (Linux) (fixed in 14.7.48855 (Linux)); from 13.2.0 (Linux), before 13.2.153995 (Linux) (fixed in 13.2.153995 (Linux)); from 14.7.0 (MacOS), before 14.7.48855 (MacOS) (fixed in 14.7.48855 (MacOS)); …

Published 2026-09-29. Last modified 2026-09-30.