An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update to the latest version.
Workaround
No workaround given by the vendor.
References
History
Tue, 29 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system. | |
| Title | Remote Session Access Control Bypass Leading to Remote Code Execution | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TV
Published:
Updated: 2026-09-29T15:42:27.283Z
Reserved: 2026-09-16T07:16:01.956Z
Link: CVE-2026-92370
No data.
Status : Received
Published: 2026-09-29T16:17:15.033
Modified: 2026-09-29T16:17:15.033
Link: CVE-2026-92370
No data.
OpenCVE Enrichment
No data.
Weaknesses