Improper Validation of File Paths in TeamViewer Desktop Clients
Summary
| CVE | CVE-2026-16444 |
|---|---|
| State | PUBLISHED |
| Assigner | TV |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-26 10:16:39 UTC |
| Updated | 2026-09-01 20:50:58 UTC |
| Description | Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.002580000 probability, percentile 0.172220000 (date 2026-09-03)
Problem Types: CWE-73 | CWE-73 CWE-73 External control of file name or path
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | TeamViewer | Full Client Host QuickSupport Portable | affected 15.0 15.81.5 custom | Windows, MacOS, Linux |
| CNA | TeamViewer | Full Client Host QuickSupport Portable For Windows 7 8 | affected 15.64.0 15.64.7 custom | Windows |
| CNA | TeamViewer | Full Client Host QuickSupport V14 For Windows | affected 14.0 14.7.48833 custom | Windows |
| CNA | TeamViewer | Full Client Host QuickSupport V14 For Linux | affected 14.0 14.7.48838 custom | Linux |
| CNA | TeamViewer | Full Client Host QuickSupport V14 For MacOS | affected 14.0 14.7.48838 custom | MacOS |
| CNA | TeamViewer | Full Client Host QuickSupport Portable V13 For Windows | affected 13.0 13.2.36229 custom | Windows |
| CNA | TeamViewer | Full Client Host QuickSupport V13 For Linux | affected 13.0 13.2.153978 custom | Linux |
| CNA | TeamViewer | Full Client Host QuickSupport V13 For MacOS | affected 13.0 13.2.153981 custom | MacOS |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.teamviewer.com/de/resources/trust-center/security-bulletins/tv-2026-1008 | [email protected] | www.teamviewer.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Jamir0quai & sam91281 (en)
Additional Advisory Data
Solutions
CNA: Update to the last available client version.
There are currently no legacy QID mappings associated with this CVE.