Description
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
Published: 2026-09-29
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

An improper access control flaw allows an authenticated remote attacker to modify the access parameters that a user has explicitly denied. By altering these settings during a session start, the attacker can invoke functionality that was meant to be restricted, potentially leading to remote execution of arbitrary code. The weakness is a classic authorization bypass identified as CWE-284.

Affected Systems

TeamViewer Full Client and Host on Windows, Linux, and macOS are affected. No specific vendor version numbers are listed; any installed instance that has not been updated to the latest release may be vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, indicating high risk, and EPSS data is unavailable. It is not currently listed in the CISA KEV catalog. Successful exploitation requires the attacker to first authenticate and then manipulate session parameters, so the attack vector is inbound remote within an established TeamViewer connection.

Generated by OpenCVE AI on September 30, 2026 at 00:54 UTC.

Remediation

Vendor Solution

Update to the latest version.


OpenCVE Recommended Actions

  • Update TeamViewer to the latest release as provided by the vendor
  • Verify and enforce user permission settings for restricted features before accepting remote sessions
  • Monitor and log session initiation events for signs of unauthorized configuration changes and consider segmenting TeamViewer traffic

Generated by OpenCVE AI on September 30, 2026 at 00:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Teamviewer
Teamviewer full Client
Teamviewer host
Vendors & Products Teamviewer
Teamviewer full Client
Teamviewer host

Tue, 29 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
Title Remote Session Access Control Bypass Leading to Remote Code Execution
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Teamviewer Full Client Host
cve-icon MITRE

Status: PUBLISHED

Assigner: TV

Published:

Updated: 2026-09-29T15:42:27.283Z

Reserved: 2026-09-16T07:16:01.956Z

Link: CVE-2026-92370

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-29T16:17:15.033

Modified: 2026-09-29T21:35:31.350

Link: CVE-2026-92370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T01:00:09Z

Weaknesses