Remote Session Access Control Bypass Leading to Remote Code Execution
Summary
| CVE | CVE-2026-92370 |
|---|---|
| State | PUBLISHED |
| Assigner | TV |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-29 16:17:15 UTC |
| Updated | 2026-09-30 16:19:25 UTC |
| Description | An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system. |
Risk And Classification
Primary CVSS: v3.1 8.8 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Problem Types: CWE-284 | CWE-284 CWE-284 Improper Access Control
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | TeamViewer | Full Client | affected 15.0 15.82 custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Full Client | affected 15.64.0 (Legacy Windows 7 & 8) 15.64.8 (Legacy Windows 7 & 8) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Full Client | affected 14.7.0 (Windows) 14.7.48855 (Windows) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Full Client | affected 13.2.0 (Windows) 13.2.36230 (Windows) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Full Client | affected 14.7.0 (Linux) 14.7.48855 (Linux) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Full Client | affected 13.2.0 (Linux) 13.2.153995 (Linux) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Full Client | affected 14.7.0 (MacOS) 14.7.48855 (MacOS) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Full Client | affected 13.2.0 (MacOS) 13.2.153994 (MacOS) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Host | affected 15.0 15.82 custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Host | affected 15.64.0 (Legacy Windows 7 & 8) 15.64.8 (Legacy Windows 7 & 8) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Host | affected 14.7.0 (Windows) 14.7.48855 (Windows) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Host | affected 13.2.0 (Windows) 13.2.36230 (Windows) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Host | affected 14.7.0 (Linux) 14.7.48855 (Linux) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Host | affected 13.2.0 (Linux) 13.2.153995 (Linux) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Host | affected 14.7.0 (MacOS) 14.7.48855 (MacOS) custom | Windows, Linux, MacOS |
| CNA | TeamViewer | Host | affected 13.2.0 (MacOS) 13.2.153994 (MacOS) custom | Windows, Linux, MacOS |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010 | [email protected] | www.teamviewer.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: We thank HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL) for the discovery and responsible disclosure. (en)
Additional Advisory Data
Solutions
CNA: Update to the latest version.
There are currently no legacy QID mappings associated with this CVE.