CVE-2026-4390
MEDIUM 5.5EPSS 0.3%
A weakness has been identified in TeamSpeak 3 Server up to 3.13.7. This affects the function process_resend_queue of the component Connection State Management. This manipulation causes use after free. The attack may be initiated remotely. Upgrading to version 3.13.8 is able to mitigate this issue. The affected component should be upgraded.
- CVSS v4.0
- 5.3 MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - CVSS v3.1
- 5.4 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L - CVSS v2.0
- 5.5 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:P - EPSS
- 0.26% chance of exploitation in the next 30 days, 17th percentile
- Published
- 2026-05-27
Proof-of-concept exploits (1)
- born0monday/teamspeak3-vulnerabilities0★ · 2026-06-03