An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
Advisories
No advisories yet.
Fixes
Solution
Update to the latest version.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Teamviewer
Teamviewer full Client Teamviewer host |
|
| Vendors & Products |
Teamviewer
Teamviewer full Client Teamviewer host |
Tue, 29 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system. | |
| Title | Remote Session Access Control Bypass Leading to Remote Code Execution | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TV
Published:
Updated: 2026-09-29T15:42:27.283Z
Reserved: 2026-09-16T07:16:01.956Z
Link: CVE-2026-92370
No data.
Status : Received
Published: 2026-09-29T16:17:15.033
Modified: 2026-09-29T16:17:15.033
Link: CVE-2026-92370
No data.
OpenCVE Enrichment
Updated: 2026-09-29T18:00:14Z
Weaknesses