Improper authorization in TeamViewer products - CVE-2026-23572

 

Improper authorization in TeamViewer products - CVE-2026-23572

Published: February 5, 2026


Vulnerability identifier: #VU122420
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23572
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass authorization checks.

The vulnerability exists due to improper authorization checks when "Allow after confirmation" option is selected. A remote authenticated user can bypass additional access control and gain access to the system without an additional user consent. 

Note, the attacker needs to be authenticated for the remote session via ID/password, Session Link, or Easy Access as a prerequisite to exploit this vulnerability.


Affected software

TeamViewer Remote Host for Windows
TeamViewer Remote Full Client for Windows
TeamViewer Full Client for Linux
TeamViewer Full Client for macOS
TeamViewer Host for Linux
TeamViewer Host for macOS

How to mitigate CVE-2026-23572

Install updates from vendor's website.

TeamViewer Remote Host for Windows - update to 15.74.5
TeamViewer Remote Full Client for Windows - update to 15.74.5
TeamViewer Full Client for Linux - update to 15.74.5
TeamViewer Full Client for macOS - update to 15.74.5
TeamViewer Host for Linux - update to 15.74.5
TeamViewer Host for macOS - update to 15.74.5

External References

Related Security Bulletins