{"id":"CVE-2026-92371","published":"2026-09-29T16:17:15.177","lastModified":"2026-09-29T21:35:31.350","description":"TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.","cvssScore":7,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-59"],"vendors":[],"products":[],"references":[{"url":"https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}