Improper Access Control in TeamViewer Client on Multiple Platforms
CVE-2026-92370

8.8HIGH

Key Information:

Vendor

Teamviewer

Vendor
CVE Published:
29 September 2026

What is CVE-2026-92370?

An improper access control vulnerability exists in the TeamViewer Full Client and Host, affecting multiple platforms including Windows, Linux, and macOS. This flaw allows authenticated remote attackers to bypass user-defined permission settings during session initiation. By altering access control parameters, an attacker may perform actions that were meant to be restricted, which can lead to unauthorized operations and may result in remote code execution on the affected systems.

Affected Version(s)

Full Client Windows 15.0 < 15.82

Full Client Windows 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)

Full Client Windows 14.7.0 (Windows) < 14.7.48855 (Windows)

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

We thank HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL) for the discovery and responsible disclosure.
.