CVE-2026-16444
Received Received - Intake

Path Traversal in TeamViewer Desktop Client

Vulnerability report for CVE-2026-16444, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: TeamViewer Germany GmbH

Description

Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
teamviewer desktop_clients 15.81.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper neutralization of path traversal sequences in TeamViewer Desktop Clients before version 15.81.5. An authenticated remote session participant can exploit file transfer or virtual file clipboard features to write files to unintended locations on the local file system. This could allow an attacker to achieve arbitrary file writes and potentially execute code with the privileges of the affected user.

Detection Guidance

Detection may involve monitoring file system changes during TeamViewer sessions. Check for unexpected file writes in user directories or system folders. Review TeamViewer logs for unusual file transfer activities. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow an attacker to write malicious files to sensitive locations on your system, potentially leading to code execution with your user privileges. This might result in data theft, system compromise, or further network infiltration if the attacker gains control of your account or system.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using affected TeamViewer versions may face compliance violations, legal penalties, and reputational damage due to potential data breaches or unauthorized system access.

Mitigation Strategies

Update TeamViewer Desktop Clients to version 15.81.5 or later. Restrict file transfer permissions in TeamViewer settings. Disable unnecessary file clipboard sharing. Monitor for unauthorized file writes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16444. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart