Improper access control in TeamViewer products - CVE-2026-92370

 

Improper access control in TeamViewer products - CVE-2026-92370

Published: September 29, 2026


Vulnerability identifier: #VU152872
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-92370
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform unauthorized actions and potentially execute arbitrary code.

The vulnerability exists due to improper access control in remote session access control during session establishment when modifying access control parameters for restricted features. A remote attacker can modify access control parameters to perform unauthorized actions and potentially execute arbitrary code.

User interaction is required.


Affected software

TeamViewer Remote Full Client for Windows
TeamViewer Host for macOS
TeamViewer Full Client for macOS
TeamViewer Full Client for Linux
TeamViewer Host for Linux
TeamViewer Remote Host for Windows

How to mitigate CVE-2026-92370

Install security update from vendor's website.

TeamViewer Remote Full Client for Windows - addressed in versions 13.2.36230, 14.7.48855, 15.64.8, 15.82
TeamViewer Remote Host for Windows - addressed in versions 13.2.36230, 14.7.48855, 15.64.8, 15.82
TeamViewer Host for macOS - addressed in versions 13.2.153994, 14.7.48855, 15.82
TeamViewer Full Client for macOS - addressed in versions 13.2.153994, 14.7.48855, 15.82
TeamViewer Full Client for Linux - addressed in versions 13.2.153995, 14.7.48855, 15.82
TeamViewer Host for Linux - addressed in versions 13.2.153995, 14.7.48855, 15.82

External References

Related Security Bulletins