{"api_version":"1","generated_at":"2026-09-11T05:29:03+00:00","cve":"CVE-2026-16444","urls":{"html":"https://cve.report/CVE-2026-16444","api":"https://cve.report/api/cve/CVE-2026-16444.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16444","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16444"},"summary":{"title":"Improper Validation of File Paths in TeamViewer Desktop Clients","description":"Improper\nneutralization of path traversal sequences in TeamViewer Desktop Clients prior\nVersion 15.81.5 allows an authenticated remote session participant to write files\nto unintended locations on the local file system via file transfer or virtual\nfile clipboard mechanisms. An attacker can leverage this behavior to achieve\narbitrary file write and potentially execute code with the privileges of the\naffected user.","state":"PUBLISHED","assigner":"TV","published_at":"2026-08-26 10:16:39","updated_at":"2026-09-01 20:50:58"},"problem_types":["CWE-73","CWE-73 CWE-73 External control of file name or path"],"metrics":[{"version":"3.1","source":"psirt@teamviewer.com","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://www.teamviewer.com/de/resources/trust-center/security-bulletins/tv-2026-1008/","name":"https://www.teamviewer.com/de/resources/trust-center/security-bulletins/tv-2026-1008/","refsource":"psirt@teamviewer.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16444","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16444","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"TeamViewer","product":"Full Client, Host, QuickSupport & Portable","version":"affected 15.0 15.81.5 custom","platforms":["Windows","MacOS","Linux"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client, Host, QuickSupport & Portable (for Windows 7 & 8)","version":"affected 15.64.0 15.64.7 custom","platforms":["Windows"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client, Host, QuickSupport (v14 for Windows)","version":"affected 14.0 14.7.48833 custom","platforms":["Windows"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client, Host, QuickSupport (v14 for Linux)","version":"affected 14.0 14.7.48838 custom","platforms":["Linux"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client, Host, QuickSupport (v14 for macOS)","version":"affected 14.0 14.7.48838 custom","platforms":["MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client, Host, QuickSupport & Portable (v13 for Windows)","version":"affected 13.0 13.2.36229 custom","platforms":["Windows"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client, Host, QuickSupport (v13 for Linux)","version":"affected 13.0 13.2.153978 custom","platforms":["Linux"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client, Host, QuickSupport (v13 for macOS)","version":"affected 13.0 13.2.153981 custom","platforms":["MacOS"]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Update to the last available client version.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Jamir0quai & sam91281","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"16444","cve":"CVE-2026-16444","epss":"0.002580000","percentile":"0.172220000","score_date":"2026-09-03","updated_at":"2026-09-04 00:08:06"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-16444","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-08-26T00:00:00+00:00","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-08-27T03:58:23.229Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["Windows","MacOS","Linux"],"product":"Full Client, Host, QuickSupport & Portable","vendor":"TeamViewer","versions":[{"lessThan":"15.81.5","status":"affected","version":"15.0","versionType":"custom"}]},{"defaultStatus":"unaffected","platforms":["Windows"],"product":"Full Client, Host, QuickSupport & Portable (for Windows 7 & 8)","vendor":"TeamViewer","versions":[{"lessThan":"15.64.7","status":"affected","version":"15.64.0","versionType":"custom"}]},{"defaultStatus":"unaffected","platforms":["Windows"],"product":"Full Client, Host, QuickSupport (v14 for Windows)","vendor":"TeamViewer","versions":[{"lessThan":"14.7.48833","status":"affected","version":"14.0","versionType":"custom"}]},{"defaultStatus":"unaffected","platforms":["Linux"],"product":"Full Client, Host, QuickSupport (v14 for Linux)","vendor":"TeamViewer","versions":[{"lessThan":"14.7.48838","status":"affected","version":"14.0","versionType":"custom"}]},{"defaultStatus":"unaffected","platforms":["MacOS"],"product":"Full Client, Host, QuickSupport (v14 for macOS)","vendor":"TeamViewer","versions":[{"lessThan":"14.7.48838","status":"affected","version":"14.0","versionType":"custom"}]},{"defaultStatus":"unaffected","platforms":["Windows"],"product":"Full Client, Host, QuickSupport & Portable (v13 for Windows)","vendor":"TeamViewer","versions":[{"lessThan":"13.2.36229","status":"affected","version":"13.0","versionType":"custom"}]},{"defaultStatus":"unaffected","platforms":["Linux"],"product":"Full Client, Host, QuickSupport (v13 for Linux)","vendor":"TeamViewer","versions":[{"lessThan":"13.2.153978","status":"affected","version":"13.0","versionType":"custom"}]},{"defaultStatus":"unaffected","platforms":["MacOS"],"product":"Full Client, Host, QuickSupport (v13 for macOS)","vendor":"TeamViewer","versions":[{"lessThan":"13.2.153981","status":"affected","version":"13.0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Jamir0quai & sam91281"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Improper\nneutralization of path traversal sequences in TeamViewer Desktop Clients prior\nVersion 15.81.5 allows an authenticated remote session participant to write files\nto unintended locations on the local file system via file transfer or virtual\nfile clipboard mechanisms. An attacker can leverage this behavior to achieve\narbitrary file write and potentially execute code with the privileges of the\naffected user.</p>"}],"value":"Improper\nneutralization of path traversal sequences in TeamViewer Desktop Clients prior\nVersion 15.81.5 allows an authenticated remote session participant to write files\nto unintended locations on the local file system via file transfer or virtual\nfile clipboard mechanisms. An attacker can leverage this behavior to achieve\narbitrary file write and potentially execute code with the privileges of the\naffected user."}],"impacts":[{"capecId":"CAPEC-126","descriptions":[{"lang":"en","value":"CAPEC-126 Path Traversal"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-73","description":"CWE-73 External control of file name or path","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-26T09:10:16.193Z","orgId":"13430f76-86eb-43b2-a71c-82c956ef31b6","shortName":"TV"},"references":[{"url":"https://www.teamviewer.com/de/resources/trust-center/security-bulletins/tv-2026-1008/"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Update to the last available client version."}],"value":"Update to the last available client version."}],"source":{"discovery":"UNKNOWN"},"title":"Improper Validation of File Paths in TeamViewer Desktop Clients","x_generator":{"engine":"Vulnogram 1.0.4"}}},"cveMetadata":{"assignerOrgId":"13430f76-86eb-43b2-a71c-82c956ef31b6","assignerShortName":"TV","cveId":"CVE-2026-16444","datePublished":"2026-08-26T09:10:16.193Z","dateReserved":"2026-07-21T07:42:28.976Z","dateUpdated":"2026-08-27T03:58:23.229Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-26 10:16:39","lastModifiedDate":"2026-09-01 20:50:58","problem_types":["CWE-73","CWE-73 CWE-73 External control of file name or path"],"metrics":{"cvssMetricV31":[{"source":"psirt@teamviewer.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-08-26T00:00:00+00:00","id":"CVE-2026-16444","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16444","Ordinal":"1","Title":"Improper Validation of File Paths in TeamViewer Desktop Clients","CVE":"CVE-2026-16444","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16444","Ordinal":"1","NoteData":"Improper\nneutralization of path traversal sequences in TeamViewer Desktop Clients prior\nVersion 15.81.5 allows an authenticated remote session participant to write files\nto unintended locations on the local file system via file transfer or virtual\nfile clipboard mechanisms. An attacker can leverage this behavior to achieve\narbitrary file write and potentially execute code with the privileges of the\naffected user.","Type":"Description","Title":"Improper Validation of File Paths in TeamViewer Desktop Clients"}]}}}