securityonline.info 8/27/2026, 9:29:23 AM · external

TeamViewer fixes critical command injection, path traversal bugs

TeamViewer fixes critical command injection, path traversal bugs
CyberSIXT Evidence Panel
Primary Source teamviewer.com
CISA KEV Not in KEV
Patch Patch Status Unknown

TEAMVIEWER has addressed two critical vulnerabilities in its desktop clients. The more critical issue, CVE-2026-19042, allows command injection leading to remote code execution, while CVE-2026-16444 permits path traversal and arbitrary file writes. Both vulnerabilities, rated 8.8 and 7.5 in severity respectively, have patches available in version 15.81.5 and later. Exploitation has not been confirmed yet, but users are advised to update immediately to mitigate risks.

The command injection flaw requires a crafted link to be clicked by the victim, whereas the path traversal issue arises from unsanitized filenames during file transfers.

View Primary Source Via securityonline.info

Article by CyberSIXT