CVE-2026-19743
Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.
- Published Sep 29, 2026
- CVSS 7.8 high
- 0.1% chance of exploitation in the next 30 days (EPSS)
- A fix is available