CVE-2026-92370
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TeamViewer | Full Client | 15.0 < 15.82 | affected |
| TeamViewer | Full Client | 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8) | affected |
| TeamViewer | Full Client | 14.7.0 (Windows) < 14.7.48855 (Windows) | affected |
| TeamViewer | Full Client | 13.2.0 (Windows) < 13.2.36230 (Windows) | affected |
| TeamViewer | Full Client | 14.7.0 (Linux) < 14.7.48855 (Linux) | affected |
| TeamViewer | Full Client | 13.2.0 (Linux) < 13.2.153995 (Linux) | affected |
| TeamViewer | Full Client | 14.7.0 (MacOS) < 14.7.48855 (MacOS) | affected |
| TeamViewer | Full Client | 13.2.0 (MacOS) < 13.2.153994 (MacOS) | affected |
| TeamViewer | Host | 15.0 < 15.82 | affected |
| TeamViewer | Host | 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8) | affected |
| TeamViewer | Host | 14.7.0 (Windows) < 14.7.48855 (Windows) | affected |
| TeamViewer | Host | 13.2.0 (Windows) < 13.2.36230 (Windows) | affected |
| TeamViewer | Host | 14.7.0 (Linux) < 14.7.48855 (Linux) | affected |
| TeamViewer | Host | 13.2.0 (Linux) < 13.2.153995 (Linux) | affected |
| TeamViewer | Host | 14.7.0 (MacOS) < 14.7.48855 (MacOS) | affected |
| TeamViewer | Host | 13.2.0 (MacOS) < 13.2.153994 (MacOS) | affected |
Weaknesses
- CWE-284: CWE-284 Improper Access Control
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.