TeamViewer has plugged five serious security holes affecting its Full Client, Host software, and components across Windows, Linux, and macOS, which if left unpatched, could let attackers bypass permissions and execute arbitrary code. Users are urged to update to version 15.82 or later immediately. As of its disclosure there’s no evidence these vulnerabilities are being exploited in the wild.
Key Vulnerabilities Uncovered
The most dangerous flaw, tracked as CVE-2026-19743, permits local, authenticated users with minimal privileges to abuse the inter-process communication system. By manipulating file paths, an attacker could write files with SYSTEM or root privileges. Everything before version 15.82, including legacy TeamViewer versions like 15.64, 14.7, and 13.2 (on certain platforms) is impacted. This issue has been rated with a CVSS score of 7.8 and relates to path traversal in local IPC.
Additional high-severity vulnerabilities include:
- CVE-2026-92369: a race condition in the Windows installer rollback process. Local attackers can swap out files in a temporary directory before a privileged installer restores them, potentially gaining full SYSTEM privileges during installs, updates, or rollbacks.
- CVE-2026-92371: a link resolution bug in Linux’s Cloud Session Recording feature. Authenticated users could redirect privileged operations due to improper file link handling. Versions 15.0 up to (but excluding) 15.82 are affected.
- CVE-2026-92368: a heap buffer overflow issue for Linux and macOS when opening malicious session recording files (.tvs). A mismatch in size handling during decompression allows arbitrary code execution under the user’s permissions. Versions 15.70 up through before 15.82 are vulnerable.
- CVE-2026-92370: the most severe, with a CVSS score of 8.8. It allows authenticated attackers to bypass user-configured restrictions and alter access control rules to perform actions normally blocked. This too affects versions earlier than 15.82.
Steps for Mitigation and Defense
Customers running TeamViewer’s Full Client or Host should immediately upgrade to 15.82 or the newest supported maintenance version. Security leaders are advised to audit current access control settings, limit who can initiate remote sessions, and restrict local access to managed endpoints.
Organisations should also monitor for abnormal installer behavior, unexpected or malformed session-recording files, and any unplanned modifications to critical system files. Tightening permissions and keeping logs will help detect attempts to exploit these vulnerabilities early.
The discovery of multiple remote-execution and privilege-escalation flaws in one of the most widely used remote access tools underscores how attractive these platforms are for attackers. As remote work and system administration increasingly rely on tools like TeamViewer, these kinds of vulnerabilities pose systemic risk. What to watch: how quickly patches are adopted, whether any of these issues are weaponized in the wild, and whether similar flaws lurk in competing remote access software.