SB2026092964 - Multiple vulnerabilities in TeamViewer



SB2026092964 - Multiple vulnerabilities in TeamViewer

Published: September 29, 2026

Security Bulletin ID SB2026092964
CSH Severity
High
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 20% Medium 20% Low 60%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Heap-based buffer overflow (CVE-ID: CVE-2026-92368)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in the processing of .tvs session recording files when decompressing recorded session data. A local user can provide a specially crafted session recording to execute arbitrary code.


2) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-92369)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to a time-of-check time-of-use race condition in the Windows installer rollback mechanism when restoring rollback backup files. A local user can replace rollback backup files in a user-writable temporary directory to escalate privileges.

Exploitation requires successful timing of the race condition during a rollback in an installation or update.


3) Improper access control (CVE-ID: CVE-2026-92370)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions and potentially execute arbitrary code.

The vulnerability exists due to improper access control in remote session access control during session establishment when modifying access control parameters for restricted features. A remote attacker can modify access control parameters to perform unauthorized actions and potentially execute arbitrary code.

User interaction is required.


4) Link following (CVE-ID: CVE-2026-92371)

CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform privileged file operations in unintended locations.

The vulnerability exists due to improper link resolution before file access in the Cloud Session Recording functionality when validating file paths and subsequently accessing files. A local user can exploit a race condition during path validation and file access to perform privileged file operations in unintended locations.


5) Path traversal (CVE-ID: CVE-2026-19743)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to improper path validation in the local IPC service when processing crafted IPC commands. A local user can send crafted IPC commands that manipulate file paths to escalate privileges.


Remediation

Install update from vendor's website.