{"id":"CVE-2026-92371","title":"TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality","summary":"TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent fil…","severity":"high","cvss":7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-59"],"vendor":"TeamViewer","product":"Full Client","affected":["full_client >= 15.0 < 15.82","Host >= 15.0 < 15.82"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T16:17:15.177","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92371","references":[{"url":"https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/","label":"psirt@teamviewer.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T16:39:33.271Z","slug":"CVE-2026-92371","body":"## Overview\n\nTeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":38.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}