Executive brief
TeamViewer is a remote access and support application used by millions to control computers remotely and provide tech support. A vulnerability in the Linux version allows an attacker to execute malicious commands on a user's computer by sending a specially crafted link through the chat feature. An attacker must be in the user's contact list or have permission to send out-of-contact messages, and the user must click the malicious link for the attack to succeed.
Technical details
This is an OS command injection vulnerability (CWE-78) in TeamViewer's chat link handling mechanism for Linux clients. The vulnerability exists in TeamViewer Full Client and Host versions prior to 15.81.5, as well as legacy versions 14 and 13. An attacker can inject arbitrary shell commands through a specially crafted URL sent via the out-of-session chat feature; execution occurs in the context of the current user. The attack requires user interaction (clicking the link) and network access, but no authentication or special privileges. The vulnerability has been patched in version 15.81.5 and corresponding updates for legacy branches (14.7.48838 and 13.2.153978).
Affected products
- TeamViewer Full Client < 15.81.5 (and legacy versions 14 < 14.7.48838, 13 < 13.2.153978)
- TeamViewer Host < 15.81.5 (and legacy versions 14 < 14.7.48838, 13 < 13.2.153978)
Timeline
- 2026-08-26: disclosed: Published by TeamViewer as TV-2026-1009 and assigned CVE-2026-19042
- 2026-08-26: patched: Version 15.81.5 and legacy updates (14.7.48838, 13.2.153978) released