CVE-2026-92368 Details
Description
TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user
A heap-based buffer overflow vulnerability has been identified in TeamViewer Full Client and Host for Linux and macOS, in versions prior to 15.82. This vulnerability arises in the processing of .tvs session recording files, where a size mismatch during the decompression of recorded session data can lead to out-of-bounds writes in the heap. An attacker could exploit this vulnerability by persuading a user to open a specially crafted session recording using the 'Play or convert recorded session...' feature, potentially allowing arbitrary code execution with the privileges of the current user.
Users are advised to update to TeamViewer version 15.82 or the latest version available. Instructions for downloading the latest version can be found on the TeamViewer website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/ | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TeamViewer Full Client | < 15.82 < 15.64.8 (semver) < 14.7.48855 (semver) < 13.2.36230 (semver) < 14.7.48855 (semver) < 13.2.153995 (semver) < 14.7.48855 (semver) < 13.2.153994 (semver) |
CPE
Remediation
| |
| TeamViewer Host | < 15.82 < 15.64.8 (semver) < 14.7.48855 (semver) < 13.2.36230 (semver) < 14.7.48855 (semver) < 13.2.153995 (semver) < 14.7.48855 (semver) < 13.2.153994 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion