CVE-2026-92371EPSS p1.0%
CVE-2026-92371CVE-2026-92371
Description
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.
Scoring
| CVSS | 7.0 () |
| Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.10% probability of exploitation · percentile 1.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |