CVE-2026-12703: TeamViewer One
High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host.
Affected products
- TeamViewer One: from 15.00, before 15.80 (fixed in 15.80)
- TeamViewer Remote: from 15.00, before 15.80 (fixed in 15.80)
- TeamViewer Tensor: from 15.00, before 15.80 (fixed in 15.80)
Published 2026-07-29. Last modified 2026-07-30.