CVE-2026-16444: Improper Validation of File Paths in TeamViewer Desktop Clients
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TeamViewer Desktop Clientsto a version that resolves this vulnerability.Fixed in 15.81.5
Event History
Frequently Asked Questions
Who needs to be able to exploit this issue?
An attacker must be an authenticated participant in a remote TeamViewer session. Exploitation also requires user interaction, as reflected by the UI:R vector.
Which TeamViewer Desktop Client versions are affected?
TeamViewer Desktop Clients prior to version 15.81.5 are affected. The provided information does not state whether any particular configuration is affected by default.
What is the impact if exploitation succeeds?
An attacker can write files to unintended locations through file transfer or the virtual file clipboard. This may enable arbitrary file write and potential code execution with the privileges of the affected local user.