Command Injection in TeamViewer Full Client and Host for Linux
CVE-2026-19042

8.8HIGH

Key Information:

Vendor

Teamviewer

Vendor
CVE Published:
26 August 2026

What is CVE-2026-19042?

A command injection vulnerability exists in TeamViewer Full Client and Host for Linux prior to version 15.81.5. This flaw allows remote attackers to execute arbitrary commands on the affected system by crafting a malicious URL intended to be sent through the out-of-session chat feature. The attack requires the targeted user to click on the link, which initiates the execution of potentially harmful commands in the context of the current user.

Affected Version(s)

Full Client Linux 15.0 < 15.81.5

Full Client Linux 14.0 < 14.7.488838

Full Client Linux 13.0 < 13.2.153978

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL)
.