Broken Access Control in TeamViewer DEX Platform (On Premises)
Summary
| CVE | CVE-2026-8381 |
|---|---|
| State | PUBLISHED |
| Assigner | TV |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-22 09:16:32 UTC |
| Updated | 2026-05-22 09:16:32 UTC |
| Description | A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain backend API endpoints do not correctly enforce authorization checks, allowing an authenticated user with low privileges to perform actions and access resources intended only for higher‑privileged roles. An attacker with low‑privileged credentials may exploit this to gain unauthorized access to administrative or sensitive functionality. |
Risk And Classification
Primary CVSS: v3.1 5.4 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
EPSS: 0.000330000 probability, percentile 0.102660000 (date 2026-05-28)
Problem Types: CWE-862 | CWE-862 CWE-862 – Missing Authorization
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
| 3.1 | CNA | CVSS | 5.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | TeamViewer | DEX On-premises | affected 9.2 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1005 | [email protected] | www.teamviewer.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: Update to the latest version (9.2 or the latest version available).
There are currently no legacy QID mappings associated with this CVE.