TL;DR
TeamViewer has patched two TeamViewer vulnerabilities in its Desktop Clients. The more severe, CVE-2026-19042, is a command injection flaw in the Linux client that enables remote code execution. A second bug, CVE-2026-16444, allows path traversal and arbitrary file writes. Both are fixed in version 15.81.5.
- Product: TeamViewer (2 products)
- Vulnerabilities: 2 flaws (CVE-2026-19042, CVE-2026-16444)
- Highest severity: 8.8 (High · CVSSv3)
- Worst impact: Command Injection in Desktop Client for Linux through Chat Link Handling
- Status: No confirmed exploitation yet; patches available
- Action: Update to 15.81.5, 14.7.488838, 13.2.153978, 15.64.7 (+4) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-19042 | 8.8 | Command Injection in Desktop Client for Linux through Chat Link Handling | 15.81.5, 14.7.488838, 13.2.153978 | Not exploited |
| CVE-2026-16444 | 7.5 | CWE-73 | 15.81.5, 15.64.7, 14.7.48833 (+4) | Not exploited |
Why It Matters
TeamViewer runs on millions of endpoints for remote support and access. These TeamViewer vulnerabilities let a remote attacker run code or write files as the current user. That access can seed malware or hand over a foothold. High CVSS scores of 8.8 and 7.5 reflect the real risk.
How the Attacks Work
CVE-2026-19042 is an OS command injection bug rated CWE-78. An attacker sends a crafted URL through the out-of-session chat feature. The victim must click the link for code to run. Notably, chat from outside contacts is disabled by default, which narrows the attack surface. Details appear in TeamViewer bulletin TV-2026-1009.
CVE-2026-16444 stems from unsanitized filenames sent by a remote peer. During file transfer or virtual clipboard use, path traversal sequences let files land in unintended locations, per bulletin TV-2026-1008.
Affected Versions
The command injection flaw hits TeamViewer Full Client and Host for Linux before 15.81.5. The path traversal flaw affects Full Client, Host, and QuickSupport on Windows, macOS, and Linux before 15.81.5. Legacy v13 and v14 branches also received fixes.
Patch and Mitigation Steps
Update to version 15.81.5 or later now. As a temporary step, users on affected Linux clients should avoid clicking any links received via chat. TeamViewer reports no known public disclosure or exploitation in the wild at publication.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!