Sceawere

Vulnerability Detail

CVE-2026-19042UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TeamViewer Linux Command Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
9h ago
Vendor
TeamViewer
Product
Full Client
Attack Type
CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking the malicious link.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-08-26T10:16:40.323Z",
  "pubdate": "2026-08-26T10:16:40.323Z",
  "executiveSummary": "A command injection vulnerability exists in TeamViewer Full Client and Host for Linux, affecting all versions prior to 15.81.5.\nThe flaw stems from improper sanitization of inputs processed via the out-of-session chat feature, which can be leveraged by a remote attacker to execute arbitrary commands on the host system.\nSuccessful exploitation results in unauthorized command execution within the security context of the user running the TeamViewer application.\nThe attack is contingent upon social engineering, as it requires the targeted user to interact with a maliciously crafted URL presented through the chat interface.\nThis vulnerability poses a significant risk to confidentiality, integrity, and availability, as it effectively allows for remote code execution (RCE) on the underlying Linux operating system.\nThe attack does not require prior authentication or high-level privileges; however, the attacker's capabilities are restricted by the permissions of the authenticated local user who clicks the link.",
  "technicalDetails": "The vulnerability resides within the URL handling mechanism of the TeamViewer Full Client and Host for Linux, specifically affecting how the application parses and executes instructions originating from the out-of-session chat module.\nRoot cause analysis indicates that the application fails to adequately sanitize or validate URIs containing special characters or shell-metacharacters before passing them to the underlying system shell or execution environment.\nThe attack flow begins when a remote attacker sends a specifically crafted URL to a victim through the TeamViewer out-of-session chat. This URL is designed to exploit the lack of input validation within the protocol handling logic.\nOnce the victim clicks the malicious URL, the TeamViewer application triggers an internal function that processes the link. Due to insufficient input filtering, the attacker-supplied payload is interpreted as a command rather than a simple URI reference.\nBecause TeamViewer runs with the privileges of the logged-in user, the injected commands inherit those same privileges. This allows the attacker to execute shell commands, retrieve sensitive files, or install malicious persistence mechanisms without triggering traditional binary execution alerts, provided the commands reside within the user's execution path.\nAffected versions include all iterations of TeamViewer Full Client and Host for Linux released prior to 15.81.5. The vulnerability is effectively a client-side injection that bypasses intended functional constraints.\nThe exploit does not require the attacker to be authenticated to the local system. The attack surface is exposed directly through the chat application's interface, meaning any remote entity capable of initiating a chat session can theoretically stage this attack.\nPost-exploitation impact includes full command execution as the user, facilitating lateral movement within the network, data exfiltration, or the deployment of further secondary payloads, depending on the current user's environmental access rights."
}
CVE-2026-19042: TeamViewer Linux Command Injection Vulnerability (HIGH Severity, CVSS: 8.8) - Sceawere