neutralization of path traversal sequences in TeamViewer Desktop Clients prior
Version 15.81.5 allows an authenticated remote session participant to write files
to unintended locations on the local file system via file transfer or virtual
file clipboard mechanisms. An attacker can leverage this behavior to achieve
arbitrary file write and potentially execute code with the privileges of the
affected user.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Teamviewer
Subscribe
|
Full Client
Subscribe
Full Client, Host, Quicksupport & Portable
Subscribe
Full Client, Host, Quicksupport & Portable (for Windows 7 & 8)
Subscribe
Full Client, Host, Quicksupport & Portable (v13 For Windows)
Subscribe
Full Client, Host, Quicksupport (v13 For Linux)
Subscribe
Full Client, Host, Quicksupport (v13 For Macos)
Subscribe
Full Client, Host, Quicksupport (v14 For Linux)
Subscribe
Full Client, Host, Quicksupport (v14 For Macos)
Subscribe
Full Client, Host, Quicksupport (v14 For Windows)
Subscribe
Host
Subscribe
|
No advisories yet.
Solution
Update to the last available client version.
Workaround
No workaround given by the vendor.
Fri, 28 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Teamviewer
Teamviewer full Client Teamviewer full Client, Host, Quicksupport & Portable Teamviewer full Client, Host, Quicksupport & Portable (for Windows 7 & 8) Teamviewer full Client, Host, Quicksupport & Portable (v13 For Windows) Teamviewer full Client, Host, Quicksupport (v13 For Linux) Teamviewer full Client, Host, Quicksupport (v13 For Macos) Teamviewer full Client, Host, Quicksupport (v14 For Linux) Teamviewer full Client, Host, Quicksupport (v14 For Macos) Teamviewer full Client, Host, Quicksupport (v14 For Windows) Teamviewer host |
|
| Vendors & Products |
Teamviewer
Teamviewer full Client Teamviewer full Client, Host, Quicksupport & Portable Teamviewer full Client, Host, Quicksupport & Portable (for Windows 7 & 8) Teamviewer full Client, Host, Quicksupport & Portable (v13 For Windows) Teamviewer full Client, Host, Quicksupport (v13 For Linux) Teamviewer full Client, Host, Quicksupport (v13 For Macos) Teamviewer full Client, Host, Quicksupport (v14 For Linux) Teamviewer full Client, Host, Quicksupport (v14 For Macos) Teamviewer full Client, Host, Quicksupport (v14 For Windows) Teamviewer host |
Wed, 26 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user. | |
| Title | Improper Validation of File Paths in TeamViewer Desktop Clients | |
| Weaknesses | CWE-73 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TV
Published:
Updated: 2026-08-27T03:58:23.229Z
Reserved: 2026-07-21T07:42:28.976Z
Link: CVE-2026-16444
Updated: 2026-08-26T13:35:57.752Z
Status : Deferred
Published: 2026-08-26T10:16:39.940
Modified: 2026-09-01T20:50:58.753
Link: CVE-2026-16444
No data.
OpenCVE Enrichment
Updated: 2026-08-28T20:33:30Z