OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-92371

HIGH · CVSS 7 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The TeamViewer Full Client and Host for Linux versions prior to 15.82 are vulnerable due to an improper path validation flaw in the Cloud Session Recording feature. This vulnerability allows a local authenticated attacker to exploit a race condition, potentially leading to unauthorized privileged file operations in unintended locations. Organizations using affected versions should prioritize patching to mitigate the risk of local attacks that could compromise system integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92371
Severity
HIGH
CVSS
7
EPSS
0.10%
Linux

Original NVD Description

TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.