CVE-2026-19743
Received Received - Intake

Improper Path Validation in TeamViewer Leading to Local Privilege Escalation

Vulnerability report for CVE-2026-19743, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: TeamViewer Germany GmbH

Description

Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
teamviewer full_client to 15.82 (exc)
teamviewer host to 15.82 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper path validation in TeamViewer's local IPC service on Windows, Linux, and macOS. A local authenticated user with low privileges can exploit it by sending crafted commands to perform arbitrary file writes with elevated privileges, leading to local privilege escalation.

Impact Analysis

An attacker with low-level access could escalate privileges to SYSTEM on Windows or root on Linux/macOS. This could allow them to execute malicious code, modify system files, or gain full control over the affected machine.

Compliance Impact

This vulnerability could lead to unauthorized access or control of systems, violating data protection requirements under GDPR and HIPAA. Organizations may face compliance breaches if exploited, resulting in legal and financial penalties.

Mitigation Strategies

Update TeamViewer to version 15.82 or later to address the improper path validation issue. Ensure all systems running TeamViewer Full Client or Host are patched immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19743. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart