TeamSpeak 3.5.6 - Insecure File Permissions Severity: HIGH Date: January 13, 2026 Affecting: TeamSpeak 3.5.6 Description TeamSpeak 3.5.6 contains an insecure file permissions vulnerability that allows local attackers to replace executable files with malicious binaries. Attackers can replace system executables like ts3client_win32.exe with custom files to potentially gain SYSTEM or Administrator-level access. Credit Aryan Chehreghani Additional Information CVE: CVE-2022-50931 CWE: CWE-732 Incorrect Permission Assignment for Critical Resource CVSS Score: 4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N ExploitDB: ExploitDB-50743 References: - TeamSpeak Official Vendor Homepage - TeamSpeak Downloads Page