Path Traversal Vulnerability in TeamViewer Desktop Clients
CVE-2026-16444

7.5HIGH

What is CVE-2026-16444?

A vulnerability exists in TeamViewer Desktop Clients prior to version 15.81.5 that stems from improper handling of path traversal sequences. This security flaw allows an authenticated participant in a remote session to manipulate file transfer and virtual file clipboard functionality, resulting in the ability to write files to unintended locations within the local file system. Exploiting this vulnerability can enable an attacker to execute arbitrary code with the user's privileges, potentially leading to unauthorized access and control over the affected system.

Affected Version(s)

Full Client, Host, QuickSupport (v13 for Linux) Linux 13.0 < 13.2.153978

Full Client, Host, QuickSupport (v13 for macOS) MacOS 13.0 < 13.2.153981

Full Client, Host, QuickSupport (v14 for Linux) Linux 14.0 < 14.7.48838

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jamir0quai & sam91281
.