{"id":"CVE-2026-92370","title":"An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session esta…","summary":"An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session esta…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-284"],"vendor":"TeamViewer","product":"Full Client","affected":["full_client >= 15.0 < 15.82","full_client >= 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)","full_client >= 14.7.0 (Windows) < 14.7.48855 (Windows)","full_client >= 13.2.0 (Windows) < 13.2.36230 (Windows)","full_client >= 14.7.0 (Linux) < 14.7.48855 (Linux)","full_client >= 13.2.0 (Linux) < 13.2.153995 (Linux)","full_client >= 14.7.0 (MacOS) < 14.7.48855 (MacOS)","full_client >= 13.2.0 (MacOS) < 13.2.153994 (MacOS)","Host >= 15.0 < 15.82","Host >= 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)","Host >= 14.7.0 (Windows) < 14.7.48855 (Windows)","Host >= 13.2.0 (Windows) < 13.2.36230 (Windows)","Host >= 14.7.0 (Linux) < 14.7.48855 (Linux)","Host >= 13.2.0 (Linux) < 13.2.153995 (Linux)","Host >= 14.7.0 (MacOS) < 14.7.48855 (MacOS)","Host >= 13.2.0 (MacOS) < 13.2.153994 (MacOS)"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T16:17:15.033","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92370","references":[{"url":"https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/","label":"psirt@teamviewer.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T16:39:33.271Z","slug":"CVE-2026-92370","body":"## Overview\n\nAn improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}