CVE-2026-92371

LOWCVSS 7.0 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-30: 309-30
Referenced assets1 URL
Full discourse3 posts
  • Juan F Gallego@jfernandogg

    CVE-2026-92370 (CVSS 8.8) en TeamViewer Full Client/Host: improper access control — un atacante autenticado remoto salta permisos de sesión y llega a RCE. Advisory TV-2026-1010 (29 sep); vendor urgió actualizar "as soon as possible". También High: path traversal CVE-2026-19743 (LPE SYSTEM/root), heap overflow CVE-2026-92368 (RCE vía .tvs recording en Linux/macOS), TOCTOU installer CVE-2026-92369, path validation CSR CVE-2026-92371. Fix: 15.82 (+ legacy 15.64.8 / 14.7.48855 / 13.2.*). Sin evidencia de explotación activa ni PoC público —igual urge por el abuso histórico de TeamViewer en ransomware. Despliega flota hoy.

    0001047
    341 followersView on X
  • Autumn Good@autumn_good_35

    CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370, CVE-2026-92371 Security Update for Multiple Vulnerabilities in TeamViewer Clients and Related Services https://www.teamviewer.com/en-us/resources/trust-center/security-bulletins/tv-2026-1010/

    00010362
    7.2K followersView on X
  • Orion84@Orion84x

    Why it matters: Five flaws in Full Client and Host on Windows, Linux, and macOS. Highest is CVE-2026-92370, a remote session access-control bypass that can lead to RCE. Others can escalate to SYSTEM or root (CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371).

    0000028
    20 followersView on X

Explore more