CVE-2026-92370: TeamViewer Full Client

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.

Affected products

  • TeamViewer Full Client: from 15.0, before 15.82 (fixed in 15.82); from 14.7.0 (Windows), before 14.7.48855 (Windows) (fixed in 14.7.48855 (Windows)); from 13.2.0 (Windows), before 13.2.36230 (Windows) (fixed in 13.2.36230 (Windows)); from 14.7.0 (Linux), before 14.7.48855 (Linux) (fixed in 14.7.48855 (Linux)); from 13.2.0 (Linux), before 13.2.153995 (Linux) (fixed in 13.2.153995 (Linux)); from 14.7.0 (MacOS), before 14.7.48855 (MacOS) (fixed in 14.7.48855 (MacOS)); …
  • TeamViewer Host: from 15.0, before 15.82 (fixed in 15.82); from 14.7.0 (Windows), before 14.7.48855 (Windows) (fixed in 14.7.48855 (Windows)); from 13.2.0 (Windows), before 13.2.36230 (Windows) (fixed in 13.2.36230 (Windows)); from 14.7.0 (Linux), before 14.7.48855 (Linux) (fixed in 14.7.48855 (Linux)); from 13.2.0 (Linux), before 13.2.153995 (Linux) (fixed in 13.2.153995 (Linux)); from 14.7.0 (MacOS), before 14.7.48855 (MacOS) (fixed in 14.7.48855 (MacOS)); …

Published 2026-09-29. Last modified 2026-09-30.