CVE-2026-92371: high-severity vulnerability in TeamViewer Full Client
Local Privilege Escalation via Improper Link Resolution in Cloud Session Recording
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Related CVEs — TeamViewer Full Client
In the same product, most dangerous first.
CVE-2026-19042HIGHCommand Injection in TeamViewer Desktop Client for Linux through Chat Link HandlingEPSS 2.0%CVE-2026-92370HIGHRemote Session Access Control Bypass Leading to Remote Code ExecutionEPSS 0.4%CVE-2025-36537HIGHIncorrect Permission Assignment for Critical Resource in TeamViewer Remote ManagementEPSS 0.2%CVE-2026-92368HIGHHeap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to Remote Code ExecutionEPSS 0.1%CVE-2025-41421MEDIUMPrivilege Escalation via Symbolic Link Spoofing in TeamViewer ClientEPSS 0.1%CVE-2026-19743HIGHImproper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop ClientsEPSS 0.1%