{"api_version":"1","generated_at":"2026-10-01T10:50:14+00:00","cve":"CVE-2026-92370","urls":{"html":"https://cve.report/CVE-2026-92370","api":"https://cve.report/api/cve/CVE-2026-92370.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-92370","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-92370"},"summary":{"title":"Remote Session Access Control Bypass Leading to Remote Code Execution","description":"An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.","state":"PUBLISHED","assigner":"TV","published_at":"2026-09-29 16:17:15","updated_at":"2026-09-30 16:19:25"},"problem_types":["CWE-284","CWE-284 CWE-284 Improper Access Control"],"metrics":[{"version":"3.1","source":"psirt@teamviewer.com","type":"Secondary","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"8.8","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/","name":"https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/","refsource":"psirt@teamviewer.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-92370","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92370","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"TeamViewer","product":"Full Client","version":"affected 15.0 15.82 custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client","version":"affected 15.64.0 (Legacy Windows 7 & 8) 15.64.8 (Legacy Windows 7 & 8) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client","version":"affected 14.7.0 (Windows) 14.7.48855 (Windows) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client","version":"affected 13.2.0 (Windows) 13.2.36230 (Windows) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client","version":"affected 14.7.0 (Linux) 14.7.48855 (Linux) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client","version":"affected 13.2.0 (Linux) 13.2.153995 (Linux) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client","version":"affected 14.7.0 (MacOS) 14.7.48855 (MacOS) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Full Client","version":"affected 13.2.0 (MacOS) 13.2.153994 (MacOS) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Host","version":"affected 15.0 15.82 custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Host","version":"affected 15.64.0 (Legacy Windows 7 & 8) 15.64.8 (Legacy Windows 7 & 8) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Host","version":"affected 14.7.0 (Windows) 14.7.48855 (Windows) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Host","version":"affected 13.2.0 (Windows) 13.2.36230 (Windows) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Host","version":"affected 14.7.0 (Linux) 14.7.48855 (Linux) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Host","version":"affected 13.2.0 (Linux) 13.2.153995 (Linux) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Host","version":"affected 14.7.0 (MacOS) 14.7.48855 (MacOS) custom","platforms":["Windows","Linux","MacOS"]},{"source":"CNA","vendor":"TeamViewer","product":"Host","version":"affected 13.2.0 (MacOS) 13.2.153994 (MacOS) custom","platforms":["Windows","Linux","MacOS"]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Update to the latest version.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"We thank HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL) for the discovery and responsible disclosure.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-92370","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2026-09-30T15:12:37.475626Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-30T15:28:18.681Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["Windows","Linux","MacOS"],"product":"Full Client","vendor":"TeamViewer","versions":[{"lessThan":"15.82","status":"affected","version":"15.0","versionType":"custom"},{"lessThan":"15.64.8 (Legacy Windows 7 & 8)","status":"affected","version":"15.64.0 (Legacy Windows 7 & 8)","versionType":"custom"},{"lessThan":"14.7.48855 (Windows)","status":"affected","version":"14.7.0 (Windows)","versionType":"custom"},{"lessThan":"13.2.36230 (Windows)","status":"affected","version":"13.2.0 (Windows)","versionType":"custom"},{"lessThan":"14.7.48855 (Linux)","status":"affected","version":"14.7.0 (Linux)","versionType":"custom"},{"lessThan":"13.2.153995 (Linux)","status":"affected","version":"13.2.0 (Linux)","versionType":"custom"},{"lessThan":"14.7.48855 (MacOS)","status":"affected","version":"14.7.0 (MacOS)","versionType":"custom"},{"lessThan":"13.2.153994 (MacOS)","status":"affected","version":"13.2.0 (MacOS)","versionType":"custom"}]},{"defaultStatus":"unaffected","platforms":["Windows","Linux","MacOS"],"product":"Host","vendor":"TeamViewer","versions":[{"lessThan":"15.82","status":"affected","version":"15.0","versionType":"custom"},{"lessThan":"15.64.8 (Legacy Windows 7 & 8)","status":"affected","version":"15.64.0 (Legacy Windows 7 & 8)","versionType":"custom"},{"lessThan":"14.7.48855 (Windows)","status":"affected","version":"14.7.0 (Windows)","versionType":"custom"},{"lessThan":"13.2.36230 (Windows)","status":"affected","version":"13.2.0 (Windows)","versionType":"custom"},{"lessThan":"14.7.48855 (Linux)","status":"affected","version":"14.7.0 (Linux)","versionType":"custom"},{"lessThan":"13.2.153995 (Linux)","status":"affected","version":"13.2.0 (Linux)","versionType":"custom"},{"lessThan":"14.7.48855 (MacOS)","status":"affected","version":"14.7.0 (MacOS)","versionType":"custom"},{"lessThan":"13.2.153994 (MacOS)","status":"affected","version":"13.2.0 (MacOS)","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"We thank HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL) for the discovery and responsible disclosure."}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.&nbsp;"}],"value":"An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system."}],"impacts":[{"capecId":"CAPEC-113","descriptions":[{"lang":"en","value":"CAPEC-113 Interface Manipulation"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-29T15:42:27.283Z","orgId":"13430f76-86eb-43b2-a71c-82c956ef31b6","shortName":"TV"},"references":[{"tags":["vendor-advisory"],"url":"https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Update to the latest version."}],"value":"Update to the latest version."}],"source":{"discovery":"UNKNOWN"},"title":"Remote Session Access Control Bypass Leading to Remote Code Execution","x_generator":{"engine":"Vulnogram 1.0.5"}}},"cveMetadata":{"assignerOrgId":"13430f76-86eb-43b2-a71c-82c956ef31b6","assignerShortName":"TV","cveId":"CVE-2026-92370","datePublished":"2026-09-29T15:42:27.283Z","dateReserved":"2026-09-16T07:16:01.956Z","dateUpdated":"2026-09-30T15:28:18.681Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-29 16:17:15","lastModifiedDate":"2026-09-30 16:19:25","problem_types":["CWE-284","CWE-284 CWE-284 Improper Access Control"],"metrics":{"cvssMetricV31":[{"source":"psirt@teamviewer.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-30T15:12:37.475626Z","id":"CVE-2026-92370","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"92370","Ordinal":"1","Title":"Remote Session Access Control Bypass Leading to Remote Code Exec","CVE":"CVE-2026-92370","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"92370","Ordinal":"1","NoteData":"An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.","Type":"Description","Title":"Remote Session Access Control Bypass Leading to Remote Code Exec"}]}}}