Skip to content

TeamViewer patches CVE-2026-92370 access-control bypass (CVSS 8.8)

TeamViewer's 15.82 release fixes five high-severity flaws, led by CVE-2026-92370 (CVSS 8.8), a session access-control bypass that can lead to code execution. No exploitation reported yet.

Published 2 min read

TeamViewer has patched five high-severity vulnerabilities in its Full Client and Host software, and is telling users to update "as soon as possible." The most serious, CVE-2026-92370 (CVSS 8.8), is a session access-control bypass an authenticated remote attacker can use to override user-configured permission settings during session establishment — a path to arbitrary code execution on the connected machine. Every fix ships in version 15.82.

The vendor's security bulletin TV-2026-1010, published September 29, is the primary account.

What's affected

The flaws sit in TeamViewer Full Client and Host for Windows, Linux, and macOS. The five CVEs:

Version 15.82 resolves all five across current and supported legacy branches.

Exploitation status

None reported. TeamViewer states it "is not aware of any public disclosure or active exploitation in the wild." There is no public proof-of-concept at time of writing, and no CVSS score has been published for the four secondary flaws — only CVE-2026-92370 carries the 8.8 rating.

Action checklist

  1. Update every TeamViewer Full Client and Host install to 15.82 — Windows, Linux, and macOS alike. Prioritize any host reachable from untrusted networks.
  2. Check managed and unattended-access deployments. Fleet-managed hosts may lag behind the auto-updater; confirm the version in your RMM or device inventory.
  3. Review who can start sessions. CVE-2026-92370 abuses permission handling at session setup — tighten allowlists and disable easy/unattended access where it isn't needed.
  4. Audit recent session logs on internet-exposed hosts for unexpected connections, given the permission-bypass nature of the top flaw.

Context

Remote-access agents are a standing initial-access target: they run with high privilege, sit on endpoints and servers alike, and are often exempted from the scrutiny applied to inbound services. A permission-bypass bug in the session-setup path is exactly the kind of primitive that turns a legitimate remote-support tool into a foothold. No exploitation is known here — but the window between a disclosed access-control bypass and a working PoC for a product this widely deployed tends to be short, which is why TeamViewer's "as soon as possible" framing is worth taking at face value.

Related stories