Description
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update to the latest version.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Tue, 29 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system. | |
| Title | Remote Session Access Control Bypass Leading to Remote Code Execution | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TV
Published:
Updated: 2026-09-29T15:42:27.283Z
Reserved: 2026-09-16T07:16:01.956Z
Link: CVE-2026-92370
No data.
Status : Received
Published: 2026-09-29T16:17:15.033
Modified: 2026-09-29T16:17:15.033
Link: CVE-2026-92370
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-284
Improper Access Control