Command injection in TeamViewer Digital Employee Experience (DEX) - CVE-2026-2695

 

Command injection in TeamViewer Digital Employee Experience (DEX) - CVE-2026-2695

Published: May 19, 2026


Vulnerability identifier: #VU131803
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-2695
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute elevated commands on devices connected to the platform.

The vulnerability exists due to improper input validation in specific instructions when processing instruction input. A remote user can inject commands in specific instructions to execute elevated commands on devices connected to the platform.

Exploitation requires at least questioner privileges.


Affected software

TeamViewer Digital Employee Experience (DEX)

How to mitigate CVE-2026-2695

Install security update from vendor's website.

TeamViewer Digital Employee Experience (DEX) - update to 9.2

External References

Related Security Bulletins