Authentication bypass using an alternate path or channel in TeamViewer Full Client for macOS and TeamViewer Remote Host for macOS - CVE-2026-12703
Published: July 29, 2026 / Updated: July 30, 2026
Vulnerability details
The vulnerability allows a remote user to bypass the configured 2fa for connections approval and establish a remote connection to an affected macos host.
The vulnerability exists due to authentication bypass using an alternate path or channel in unattended access when handling connections approval via unattended access. A remote privileged user can use unattended access to bypass the configured 2fa for connections approval and establish a remote connection to an affected macos host.
The issue affects macos hosts where unattended access is configured and requires device management permissions for pre-authenticated macos devices. TeamViewer conditional access policies are not bypassed.
Affected software
TeamViewer Remote Host for macOS
How to mitigate CVE-2026-12703
TeamViewer Remote Host for macOS - update to 15.80