MajorCritical vulnerability
CVE-2026-92370 (CVSS 8.8)
NVD · officialPublished Sep 29, 2026Risk 37/100
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.
Technical details
CVSS
8.8
AV:NetworkAC:LowPR:NoneUI:RequiredC:HighI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source