CVE-2026-92370 PUBLISHED

Remote Session Access Control Bypass Leading to Remote Code Execution

Assigner: TV
Reserved: 16.09.2026 Published: 29.09.2026 Updated: 29.09.2026

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor TeamViewer
Product Full Client
Versions Default: unaffected
  • affected from 15.0 to 15.82 (excl.)
  • affected from 15.64.0 (Legacy Windows 7 & 8) to 15.64.8 (Legacy Windows 7 & 8) (excl.)
  • affected from 14.7.0 (Windows) to 14.7.48855 (Windows) (excl.)
  • affected from 13.2.0 (Windows) to 13.2.36230 (Windows) (excl.)
  • affected from 14.7.0 (Linux) to 14.7.48855 (Linux) (excl.)
  • affected from 13.2.0 (Linux) to 13.2.153995 (Linux) (excl.)
  • affected from 14.7.0 (MacOS) to 14.7.48855 (MacOS) (excl.)
  • affected from 13.2.0 (MacOS) to 13.2.153994 (MacOS) (excl.)
Vendor TeamViewer
Product Host
Versions Default: unaffected
  • affected from 15.0 to 15.82 (excl.)
  • affected from 15.64.0 (Legacy Windows 7 & 8) to 15.64.8 (Legacy Windows 7 & 8) (excl.)
  • affected from 14.7.0 (Windows) to 14.7.48855 (Windows) (excl.)
  • affected from 13.2.0 (Windows) to 13.2.36230 (Windows) (excl.)
  • affected from 14.7.0 (Linux) to 14.7.48855 (Linux) (excl.)
  • affected from 13.2.0 (Linux) to 13.2.153995 (Linux) (excl.)
  • affected from 14.7.0 (MacOS) to 14.7.48855 (MacOS) (excl.)
  • affected from 13.2.0 (MacOS) to 13.2.153994 (MacOS) (excl.)

Solutions

Update to the latest version.

Credits

  • We thank HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL) for the discovery and responsible disclosure. finder

References

Problem Types

  • CWE-284 Improper Access Control CWE

Impacts

  • CAPEC-113 Interface Manipulation