CVE-2026-92370 Details
Description
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
A vulnerability allowing access control bypass in TeamViewer Full Client, Host, and related modules on Windows, Linux, and macOS has been identified. This vulnerability enables an authenticated remote attacker to override user-configured permission settings during session establishment. By altering access control parameters for restricted features, an attacker could execute actions explicitly denied by the victim's configuration, potentially leading to unauthorized actions and remote code execution on the target system.
Users are advised to update to TeamViewer version 15.82 or the latest available version. Instructions for downloading the latest version can be found on the TeamViewer website. For those using legacy versions, TeamViewer version 15.82 is available, as well as the latest versions of TeamViewer Full Client and Host for Windows, Linux, and macOS.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/ | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| TeamViewer Full Client | < 15.82 15.64 < 15.64.8 (semver) 14.7 < 14.7.48855 (semver) 13.2 < 13.2.36230 (semver) 14.7 < 14.7.48855 (semver) 13.2 < 13.2.153995 (semver) 14.7 < 14.7.48855 (semver) 13.2 < 13.2.153994 (semver) |
CPE
Remediation
| |
| TeamViewer Host | < 15.82 15.64 < 15.64.8 (semver) 14.7 < 14.7.48855 (semver) 13.2 < 13.2.36230 (semver) 14.7 < 14.7.48855 (semver) 13.2 < 13.2.153995 (semver) 14.7 < 14.7.48855 (semver) 13.2 < 13.2.153994 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion