Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer products - CVE-2026-92369

 

Time-of-check Time-of-use (TOCTOU) Race Condition in TeamViewer products - CVE-2026-92369

Published: September 29, 2026


Vulnerability identifier: #VU152871
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-92369
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges.

The vulnerability exists due to a time-of-check time-of-use race condition in the Windows installer rollback mechanism when restoring rollback backup files. A local user can replace rollback backup files in a user-writable temporary directory to escalate privileges.

Exploitation requires successful timing of the race condition during a rollback in an installation or update.


Affected software

TeamViewer Remote Full Client for Windows
TeamViewer Host for macOS
TeamViewer Full Client for macOS
TeamViewer Full Client for Linux
TeamViewer Host for Linux
TeamViewer Remote Host for Windows

How to mitigate CVE-2026-92369

Install security update from vendor's website.

TeamViewer Remote Full Client for Windows - addressed in versions 13.2.36230, 14.7.48855, 15.64.8, 15.82
TeamViewer Remote Host for Windows - addressed in versions 13.2.36230, 14.7.48855, 15.64.8, 15.82
TeamViewer Host for macOS - addressed in versions 13.2.153994, 14.7.48855, 15.82
TeamViewer Full Client for macOS - addressed in versions 13.2.153994, 14.7.48855, 15.82
TeamViewer Full Client for Linux - addressed in versions 13.2.153995, 14.7.48855, 15.82
TeamViewer Host for Linux - addressed in versions 13.2.153995, 14.7.48855, 15.82

External References

Related Security Bulletins