CVE-2026-16444: Improper Validation of File Paths in TeamViewer Desktop Clients

Published Aug 26, 2026
·
Updated

Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user.

Affected Software

1 affected component
TeamViewer TeamViewer Desktop Clients<15.81.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade TeamViewer Desktop Clients to a version that resolves this vulnerability.

    Fixed in 15.81.5

Event History

Aug 26, 2026
CVE Published
via MITRE·09:10 AM
Data Sourced
via MITRE·09:10 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who needs to be able to exploit this issue?

An attacker must be an authenticated participant in a remote TeamViewer session. Exploitation also requires user interaction, as reflected by the UI:R vector.

2

Which TeamViewer Desktop Client versions are affected?

TeamViewer Desktop Clients prior to version 15.81.5 are affected. The provided information does not state whether any particular configuration is affected by default.

3

What is the impact if exploitation succeeds?

An attacker can write files to unintended locations through file transfer or the virtual file clipboard. This may enable arbitrary file write and potential code execution with the privileges of the affected local user.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203