TeamViewer has addressed a critical vulnerability, identified as CVE-2026-16444, that could allow attackers to execute code remotely. This issue, highlighted in the security bulletin TV-2026-1008, was published on August 26, 2026. It primarily affects TeamViewer Remote, Tensor, and ONE deployments with certain desktop client components.
Vulnerability Details and Impact
The vulnerability arises from inadequate validation of file paths within TeamViewer Desktop Clients. This flaw permits filenames from remote peers to bypass checks, potentially allowing files to be created in unintended locations on the recipient’s system.
An attacker, authenticated in a remote session, can exploit this by using path traversal sequences. This method can redirect files meant for specific directories to other areas within the local file system, risking overwriting or unauthorized file placement.
Exploitation and Affected Versions
If an attacker successfully places a malicious file in a sensitive directory, it could lead to remote code execution. The flaw, with a CVSS score of 7.5, is classified as Important. Exploitation requires network access and user interaction during a session, affecting versions before 15.81.5 on Windows, macOS, and Linux.
Organizations using older or legacy versions must update to secure releases. For Windows 7 and 8, the update requirement is version 15.64.7 or higher. TeamViewer 14 needs to be updated to 14.7.48833+ for Windows and 14.7.48838+ for Linux/macOS, while version 13 requires specific updates for each operating system.
Mitigation Strategies and Recommendations
Due to the need for authenticated access, the risk of opportunistic attacks is low, but the threat of compromised accounts remains. Attackers might exploit this vulnerability through stolen credentials or active sessions, using legitimate-looking file transfers.
TeamViewer has not observed any public exploitation of this flaw. The vulnerability was responsibly reported by researchers Jamir0quai and sam91281 through the bug bounty program. Administrators are urged to update all TeamViewer installations to at least version 15.81.5.
Organizations should also scrutinize remote session logs, limit file transfers, enforce multi-factor authentication, and monitor for unusual file writes. These measures are crucial to prevent unauthorized access and maintain system integrity.
