« Volver al listado

CVE-2026-19042

Estado: AplazadaAlta (8.8)—

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking the malicious link.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS con UI:R (requiere interacción del usuario) y la descripción explícita de hacer clic en un enlace malicioso confirman T1203. CWE-78 (command injection) y la ejecución de comandos arbitrarios justifican T1059 como impacto.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-19042",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-19042",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-08-26T13:01:56.742837Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@teamviewer.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@teamviewer.com",
      "affectedData": [
        {
          "vendor": "TeamViewer",
          "product": "Full Client",
          "versions": [
            {
              "status": "affected",
              "version": "15.0",
              "lessThan": "15.81.5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "14.0",
              "lessThan": "14.7.488838",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "13.0",
              "lessThan": "13.2.153978",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TeamViewer",
          "product": "Host",
          "versions": [
            {
              "status": "affected",
              "version": "15.0",
              "lessThan": "15.81.5",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "14.0",
              "lessThan": "14.7.488838",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "13.0",
              "lessThan": "13.2.153978",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-08-26T10:16:40.323",
  "references": [
    {
      "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1009/",
      "source": "psirt@teamviewer.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@teamviewer.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-78"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A command injection vulnerability in TeamViewer Full\nClient and Host for Linux prior to version 15.81.5 allows a remote attacker to\nexecute arbitrary commands in the context of the current user via a specially\ncrafted URL sent through the out-of-session chat feature. Exploitation requires\nuser interaction by clicking the malicious link."
    }
  ],
  "lastModified": "2026-09-01T20:50:58.753",
  "sourceIdentifier": "psirt@teamviewer.com"
}