CVE-2026-19042: Command Injection in TeamViewer Desktop Client for Linux through Chat Link Handling
A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking the malicious link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TeamViewer Full Client and Host for Linuxto a version that resolves this vulnerability.Fixed in 15.81.5
Event History
Frequently Asked Questions
Which installations are affected?
TeamViewer Full Client and Host for Linux versions prior to 15.81.5 are affected. The issue is in handling URLs received through the out-of-session chat feature.
What does an attacker need to exploit this?
An attacker needs to send a specially crafted URL through out-of-session chat and persuade the user to click it. No attacker privileges are required before exploitation.
What level of access could successful exploitation provide?
Successful exploitation can execute arbitrary commands in the context of the current user. The reported impact includes high confidentiality, integrity, and availability consequences.
How can this be remediated?
Update affected TeamViewer Full Client and Host installations for Linux to version 15.81.5 or later.