---
id: CVE-2026-92370
title: >-
  An improper access control vulnerability in TeamViewer Full Client, Host, and
  related affected modules on Windows, Linux, and macOS allows an authenticated
  remote attacker to bypass user-configured permission settings during session
  esta…
summary: >-
  An improper access control vulnerability in TeamViewer Full Client, Host, and
  related affected modules on Windows, Linux, and macOS allows an authenticated
  remote attacker to bypass user-configured permission settings during session
  esta…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-284
vendor: TeamViewer
product: Full Client
affected:
  - full_client >= 15.0 < 15.82
  - >-
    full_client >= 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 &
    8)
  - full_client >= 14.7.0 (Windows) < 14.7.48855 (Windows)
  - full_client >= 13.2.0 (Windows) < 13.2.36230 (Windows)
  - full_client >= 14.7.0 (Linux) < 14.7.48855 (Linux)
  - full_client >= 13.2.0 (Linux) < 13.2.153995 (Linux)
  - full_client >= 14.7.0 (MacOS) < 14.7.48855 (MacOS)
  - full_client >= 13.2.0 (MacOS) < 13.2.153994 (MacOS)
  - Host >= 15.0 < 15.82
  - Host >= 15.64.0 (Legacy Windows 7 & 8) < 15.64.8 (Legacy Windows 7 & 8)
  - Host >= 14.7.0 (Windows) < 14.7.48855 (Windows)
  - Host >= 13.2.0 (Windows) < 13.2.36230 (Windows)
  - Host >= 14.7.0 (Linux) < 14.7.48855 (Linux)
  - Host >= 13.2.0 (Linux) < 13.2.153995 (Linux)
  - Host >= 14.7.0 (MacOS) < 14.7.48855 (MacOS)
  - Host >= 13.2.0 (MacOS) < 13.2.153994 (MacOS)
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T16:17:15.033'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92370'
references:
  - url: >-
      https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/
    label: psirt@teamviewer.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T16:39:33.271Z'
---

## Overview

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
