CVE-2026-92371: TeamViewer Full Client
High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.
Affected products
- TeamViewer Full Client: from 15.0, before 15.82 (fixed in 15.82)
- TeamViewer Host: from 15.0, before 15.82 (fixed in 15.82)
Published 2026-09-29. Last modified 2026-09-30.