CVE-2026-16444
Last modified
CVE-2026-16444 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user.. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Improper neutralization of path traversal sequences in TeamViewer Desktop Clients prior Version 15.81.5 allows an authenticated remote session participant to write files to unintended locations on the local file system via file transfer or virtual file clipboard mechanisms. An attacker can leverage this behavior to achieve arbitrary file write and potentially execute code with the privileges of the affected user.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| TeamViewer | Full Client, Host, QuickSupport & Portable | >= 15.0, < 15.81.5 |
| TeamViewer | Full Client, Host, QuickSupport & Portable (for Windows 7 & 8) | >= 15.64.0, < 15.64.7 |
| TeamViewer | Full Client, Host, QuickSupport (v14 for Windows) | >= 14.0, < 14.7.48833 |
| TeamViewer | Full Client, Host, QuickSupport (v14 for Linux) | >= 14.0, < 14.7.48838 |
| TeamViewer | Full Client, Host, QuickSupport (v14 for macOS) | >= 14.0, < 14.7.48838 |
| TeamViewer | Full Client, Host, QuickSupport & Portable (v13 for Windows) | >= 13.0, < 13.2.36229 |
| TeamViewer | Full Client, Host, QuickSupport (v13 for Linux) | >= 13.0, < 13.2.153978 |
| TeamViewer | Full Client, Host, QuickSupport (v13 for macOS) | >= 13.0, < 13.2.153981 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-16444?
How severe is CVE-2026-16444?
How do I fix CVE-2026-16444?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-16439In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trac…9.1
- CVE-2026-1644The WP Frontend Profile plugin for WordPress is vulnerable t…4.3
- CVE-2026-16440In Eclipse OpenJ9 versions up to 0.60, a crafted .class file…5.7
- CVE-2026-16441In Eclipse OpenJ9 versions up to 0.60, when executing class …9.6
- CVE-2026-16442A flaw was found in the SAML broker component of Keycloak, w…9.8
- CVE-2026-16443A flaw was found in the SAML metadata import functionality o…9.1
- CVE-2026-16445A flaw was found in dracut. A remote attacker on the adjacen…7.5
- CVE-2026-16447A vulnerability has been found in D-Link DNS-320 1.0.2. Impa…7.3
- CVE-2026-16448A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-3…6.3
- CVE-2026-16449A vulnerability was determined in zsadmin2025 ZS-Admin up to…6.3
- CVE-2026-1645The Hostel plugin for WordPress is vulnerable to Stored Cros…4.4
- CVE-2026-16450A vulnerability was identified in zsadmin2025 ZS-Admin up to…4.3
Are you affected by CVE-2026-16444?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
