CVE-2026-19743 Overview
CVE-2026-19743 is a local privilege escalation vulnerability in the TeamViewer Full Client and Host applications on Windows, Linux, and macOS. The flaw resides in the local Inter-Process Communication (IPC) service and stems from improper path validation. A local authenticated user with low privileges can send crafted IPC commands to the service daemon and manipulate file paths, resulting in arbitrary file writes performed with NT AUTHORITY\SYSTEM or root privileges. TeamViewer addressed the issue in version 15.82.
Critical Impact
Any low-privileged local user on an affected endpoint can escalate to SYSTEM or root by abusing the TeamViewer IPC daemon to write arbitrary files.
Affected Products
- TeamViewer Full Client on Windows, Linux, and macOS prior to version 15.82
- TeamViewer Host on Windows, Linux, and macOS prior to version 15.82
- Deployments running the local IPC service daemon shipped with these builds
Discovery Timeline
- 2026-09-29 - CVE-2026-19743 published to the National Vulnerability Database (NVD)
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-19743
Vulnerability Analysis
The TeamViewer service daemon exposes a local IPC interface used by the client UI and helper components to request privileged operations. The daemon runs as SYSTEM on Windows and as root on Linux and macOS. When the service processes file-related IPC commands, it fails to properly validate the supplied path parameters. A local attacker can craft an IPC message that references an arbitrary destination path, including sensitive system locations. The daemon then performs the write operation using its elevated token, bypassing the access controls that would otherwise apply to the caller. This class of flaw maps to Improper Limitation of a Pathname to a Restricted Directory [CWE-22].
Root Cause
The root cause is missing or insufficient canonicalization and allow-listing of file paths received over the local IPC channel. The service trusts caller-supplied paths without validating that they reside within an approved directory or belong to the invoking user. Path traversal sequences and absolute paths pointing to protected locations are accepted and honored.
Attack Vector
Exploitation requires local authenticated access with low privileges and no user interaction. An attacker connects to the TeamViewer local IPC endpoint and issues a crafted command that supplies a target file path under a directory protected by SYSTEM or root. Because the daemon executes the write with elevated privileges, the attacker can overwrite or create files such as scheduled task definitions, service binaries, DLLs in privileged search paths, or systemd unit files, achieving code execution as SYSTEM or root.
No public proof-of-concept exploit is listed in the enriched data. See the TeamViewer Security Bulletin TV-2026-1010 for vendor-supplied technical detail.
Detection Methods for CVE-2026-19743
Indicators of Compromise
- Unexpected file writes performed by the TeamViewer service process (TeamViewer_Service.exe on Windows, teamviewerd on Linux and macOS) to directories outside its normal working paths.
- New or modified executables, DLLs, scripts, or scheduled task and systemd unit files created by the TeamViewer daemon in system directories.
- Anomalous local IPC connections to the TeamViewer service from non-TeamViewer processes or from low-privileged user sessions.
Detection Strategies
- Monitor process lineage where the TeamViewer service parent spawns unexpected child processes or writes to protected paths such as C:\Windows\System32, /etc, /usr/lib/systemd/system, or /Library/LaunchDaemons.
- Alert on file creation events in privileged autorun locations authored by the TeamViewer service account.
- Correlate low-privileged user sessions with subsequent SYSTEM or root process creation events on hosts running vulnerable TeamViewer versions.
Monitoring Recommendations
- Enable File Integrity Monitoring on privileged directories and known persistence locations across Windows, Linux, and macOS endpoints.
- Collect endpoint telemetry for IPC and named pipe activity associated with the TeamViewer daemon and forward it to a centralized analytics platform.
- Track the installed TeamViewer version across the fleet and flag any host still running a build earlier than 15.82.
How to Mitigate CVE-2026-19743
Immediate Actions Required
- Upgrade all TeamViewer Full Client and Host installations to version 15.82 or later on Windows, Linux, and macOS.
- Inventory endpoints and remote-access servers to identify unmanaged or outdated TeamViewer deployments.
- Restrict local logon rights on systems running TeamViewer to reduce the population of accounts able to reach the IPC endpoint.
Patch Information
TeamViewer resolved the improper path validation in version 15.82 of the Full Client and Host. Refer to the TeamViewer Security Bulletin TV-2026-1010 for build numbers and platform-specific download links.
Workarounds
- If patching is delayed, uninstall or disable the TeamViewer service on hosts where remote access is not required.
- Limit interactive and remote local access to trusted administrators until affected hosts are updated.
- Apply application allow-listing to prevent unauthorized processes from communicating with the TeamViewer local IPC endpoint.
# Verify installed TeamViewer version on each platform
# Windows (PowerShell)
Get-ItemProperty 'HKLM:\SOFTWARE\TeamViewer' | Select-Object Version
# Linux
teamviewer --version
# macOS
defaults read /Applications/TeamViewer.app/Contents/Info.plist CFBundleShortVersionString
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.