Improper authorization in TeamViewer products - CVE-2026-23572
Published: February 5, 2026
Vulnerability details
The vulnerability allows a remote user to bypass authorization checks.
The vulnerability exists due to improper authorization checks when "Allow after confirmation" option is selected. A remote authenticated user can bypass additional access control and gain access to the system without an additional user consent.
Note, the attacker needs to be authenticated for the remote session via ID/password, Session Link, or Easy Access as a prerequisite to exploit this vulnerability.
Affected software
TeamViewer Remote Full Client for Windows
TeamViewer Full Client for Linux
TeamViewer Full Client for macOS
TeamViewer Host for Linux
TeamViewer Host for macOS
How to mitigate CVE-2026-23572
TeamViewer Remote Full Client for Windows - update to 15.74.5
TeamViewer Full Client for Linux - update to 15.74.5
TeamViewer Full Client for macOS - update to 15.74.5
TeamViewer Host for Linux - update to 15.74.5
TeamViewer Host for macOS - update to 15.74.5