Command injection in TeamViewer Digital Employee Experience (DEX) - CVE-2026-2695
Published: May 19, 2026
Vulnerability details
The vulnerability allows a remote user to execute elevated commands on devices connected to the platform.
The vulnerability exists due to improper input validation in specific instructions when processing instruction input. A remote user can inject commands in specific instructions to execute elevated commands on devices connected to the platform.
Exploitation requires at least questioner privileges.