SB2026092964 - Multiple vulnerabilities in TeamViewer
Published: September 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 vulnerabilities.
1) Heap-based buffer overflow (CVE-ID: CVE-2026-92368)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the processing of .tvs session recording files when decompressing recorded session data. A local user can provide a specially crafted session recording to execute arbitrary code.
2) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-92369)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a time-of-check time-of-use race condition in the Windows installer rollback mechanism when restoring rollback backup files. A local user can replace rollback backup files in a user-writable temporary directory to escalate privileges.
Exploitation requires successful timing of the race condition during a rollback in an installation or update.
3) Improper access control (CVE-ID: CVE-2026-92370)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions and potentially execute arbitrary code.
The vulnerability exists due to improper access control in remote session access control during session establishment when modifying access control parameters for restricted features. A remote attacker can modify access control parameters to perform unauthorized actions and potentially execute arbitrary code.
User interaction is required.
4) Link following (CVE-ID: CVE-2026-92371)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform privileged file operations in unintended locations.
The vulnerability exists due to improper link resolution before file access in the Cloud Session Recording functionality when validating file paths and subsequently accessing files. A local user can exploit a race condition during path validation and file access to perform privileged file operations in unintended locations.
5) Path traversal (CVE-ID: CVE-2026-19743)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper path validation in the local IPC service when processing crafted IPC commands. A local user can send crafted IPC commands that manipulate file paths to escalate privileges.
Remediation
Install update from vendor's website.