CVE-2026-12703

Summary

TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host.

Affected Software

VendorProductVersion RangeStatus
TeamViewerRemote15.00 < 15.80affected
TeamViewerTensor15.00 < 15.80affected
TeamViewerONE15.00 < 15.80affected

Weaknesses

  • CWE-288: CWE-288 Authentication bypass using an alternate path or channel

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References