OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-19743

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The TeamViewer Full Client and Host on Windows and Linux prior to version 15.82 are vulnerable due to improper path validation in the local IPC service, allowing authenticated users with low privileges to execute arbitrary file writes with elevated privileges. This flaw can lead to local privilege escalation, enabling attackers to gain unauthorized access to sensitive system resources. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation by local users.

CVE
CVE-2026-19743
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Windows Linux

Original NVD Description

Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.