CVE-2026-92370

Summary

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.

Affected Software

VendorProductVersion RangeStatus
TeamViewerFull Client15.0 < 15.82affected
TeamViewerFull Client15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)affected
TeamViewerFull Client14.7.0 (Windows) < 14.7.48855 (Windows)affected
TeamViewerFull Client13.2.0 (Windows) < 13.2.36230 (Windows)affected
TeamViewerFull Client14.7.0 (Linux) < 14.7.48855 (Linux)affected
TeamViewerFull Client13.2.0 (Linux) < 13.2.153995 (Linux)affected
TeamViewerFull Client14.7.0 (MacOS) < 14.7.48855 (MacOS)affected
TeamViewerFull Client13.2.0 (MacOS) < 13.2.153994 (MacOS)affected
TeamViewerHost15.0 < 15.82affected
TeamViewerHost15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)affected
TeamViewerHost14.7.0 (Windows) < 14.7.48855 (Windows)affected
TeamViewerHost13.2.0 (Windows) < 13.2.36230 (Windows)affected
TeamViewerHost14.7.0 (Linux) < 14.7.48855 (Linux)affected
TeamViewerHost13.2.0 (Linux) < 13.2.153995 (Linux)affected
TeamViewerHost14.7.0 (MacOS) < 14.7.48855 (MacOS)affected
TeamViewerHost13.2.0 (MacOS) < 13.2.153994 (MacOS)affected

Weaknesses

  • CWE-284: CWE-284 Improper Access Control

References