Path Traversal Vulnerability in TeamViewer Desktop Clients
CVE-2026-16444
Key Information:
What is CVE-2026-16444?
CVE-2026-16444 is a path traversal vulnerability found in TeamViewer Desktop Clients prior to version 15.81.5. TeamViewer is a widely used remote access and remote desktop software that facilitates online support, remote control, and file sharing across devices. This vulnerability arises due to improper handling of path traversal sequences, which enables an authenticated user during a remote session to manipulate file transfers. Specifically, it allows for the unauthorized writing of files to locations on the local file system. An attacker can exploit this flaw to execute arbitrary file writes and, potentially, run code with the same privileges as the affected user. This could lead to severe consequences for organizations, given the nature of remote access in their operations.
Potential impact of CVE-2026-16444
-
Unauthorized File Access and Manipulation: Exploiting the vulnerability allows attackers to write files to unintended locations, which could compromise sensitive data, overwrite existing files, or introduce malicious files into a user's system.
-
Privilege Escalation and Remote Code Execution: Should the attacker manage to write executable files or scripts, they could execute code within the context of the affected user, potentially leading to a complete system compromise or unauthorized access to critical systems and data.
-
Data Integrity and Operational Disruption: The ability to manipulate files can lead to corruption or loss of data. Organizations relying on TeamViewer for remote support may experience disruptions in operations, affecting service delivery and customer support. This could result in financial losses and damage to reputations.
Affected Version(s)
Full Client, Host, QuickSupport (v13 for Linux) Linux 13.0 < 13.2.153978
Full Client, Host, QuickSupport (v13 for macOS) MacOS 13.0 < 13.2.153981
Full Client, Host, QuickSupport (v14 for Linux) Linux 14.0 < 14.7.48838
