CVE-2026-19042

8.8

TeamViewer · Full Client and Host for Linux

A command injection vulnerability in TeamViewer for Linux allows remote attackers to execute arbitrary commands via a specially crafted URL sent through the out-of-session chat feature.

Executive summary

A high severity command injection vulnerability in TeamViewer for Linux allows remote attackers to execute arbitrary code via malicious links, posing a significant risk to endpoint security.

Vulnerability

This is an OS command injection vulnerability (CWE-78) triggered when an unauthenticated attacker sends a specially crafted URL via the out-of-session chat feature. Successful exploitation requires the victim to interact with the malicious link, at which point commands execute in the context of the current user.

Business impact

The ability for a remote attacker to execute arbitrary commands on a workstation or server can lead to a full system compromise, unauthorized data exfiltration, or the deployment of ransomware. With a CVSS score of 8.8, this vulnerability represents a high risk to business operations, as it bypasses standard access controls to grant the attacker the privileges of the logged-in user.

Remediation

Immediate Action: Update TeamViewer Full Client and Host for Linux to version 15.81.5 or later, or the corresponding patched releases for versions 14 and 13, as specified in the vendor security bulletin.

Proactive Monitoring: Monitor system logs for suspicious process spawning or unexpected network connections originating from the TeamViewer application process.

Compensating Controls: Advise users to exercise extreme caution when clicking links within the TeamViewer chat interface and implement endpoint protection software to detect and block malicious command shell invocations.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for full system compromise, organizations should prioritize patching affected Linux endpoints immediately. System administrators must ensure that all instances of TeamViewer are updated to the vendor-recommended versions to eliminate the command injection vector and protect against potential unauthorized access.

Sources

Originally found and disclosed by HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL), per the CVE Program record.