Description
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
Published: 2026-09-29
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Update to the latest version.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
Title Remote Session Access Control Bypass Leading to Remote Code Execution
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TV

Published:

Updated: 2026-09-29T15:42:27.283Z

Reserved: 2026-09-16T07:16:01.956Z

Link: CVE-2026-92370

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T16:17:15.033

Modified: 2026-09-29T16:17:15.033

Link: CVE-2026-92370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses