News Security

TeamViewer patches five vulnerabilities in client and host software

TeamViewer has released version 15.82 to address five vulnerabilities in its Full Client and Host software for Windows, Linux, and macOS. The most serious issue, CVE-2026-92370, can allow an authenticated remote attacker to bypass configured session permissions and potentially execute code on a target system.

The company urged customers to update as soon as possible. TeamViewer said the vulnerabilities affect versions before 15.82 and that fixes are also available through supported maintenance and legacy releases. The advisory was reported by BleepingComputer, while the vulnerability details are recorded in the NVD entries and TeamViewer’s TV-2026-1010 security bulletin.

What the vulnerabilities affect

The five issues cover remote-session access controls, local privilege escalation, session recordings, and file handling:

  • CVE-2026-92370: An improper access-control flaw affecting TeamViewer Full Client, Host, and related modules on Windows, Linux, and macOS. An authenticated remote attacker may modify access-control parameters during session establishment and perform actions that the user had denied. The issue may lead to remote code execution.
  • CVE-2026-19743: An improper path-validation flaw in the local IPC service on Windows, Linux, and macOS. A low-privileged local authenticated user may use crafted IPC commands to write files with elevated privileges, potentially escalating to NT AUTHORITY\\SYSTEM or root.
  • CVE-2026-92368: A heap-based buffer overflow in the handling of .tvs session-recording files on Linux and macOS. Opening a specially crafted recording through the playback or conversion feature may allow code execution with the current user’s privileges.
  • CVE-2026-92369: A time-of-check to time-of-use race condition in the Windows installer rollback mechanism. A local low-privileged attacker who wins the timing window during an installation or update rollback may replace files and escalate privileges to NT AUTHORITY\\SYSTEM.
  • CVE-2026-92371: An improper path-validation flaw in the Cloud Session Recording feature on Linux. A local authenticated attacker may cause privileged file operations to occur in unintended locations.

The exact conditions differ across the issues. Some require local access or authentication, while CVE-2026-92370 involves an authenticated remote attacker and configured TeamViewer session permissions.

Why it matters

TeamViewer is designed to provide remote access and control, so weaknesses in session authorization can affect the boundary between what a user permits and what a connected party can actually do. The other flaws could be relevant to systems where a local user can interact with the client, installer, session recordings, or related services.

TeamViewer said it is not aware of public exploit code or active exploitation in the wild. That statement describes the company’s current awareness; it does not remove the need to update software that is exposed to remote connections or installed on shared systems.

What TeamViewer users should do

Check the installed TeamViewer Full Client or Host version and update to 15.82 or to the applicable fixed release for the maintenance or legacy branch in use. Organizations should include unattended hosts and centrally managed installations in that review, not only the desktop clients used for support sessions.

Until systems are updated, administrators can at least review which hosts are reachable through TeamViewer and whether session permissions match the actions users intend to allow. The available evidence does not establish that temporary configuration changes eliminate the vulnerabilities, so updating remains the confirmed remediation.

Stay Updated with ToolsLib! 🚀
Join our community to receive the latest cybersecurity tips, software updates, and exclusive insights straight to your inbox!

Discover more from ToolsLib Blog

Subscribe now to keep reading and get access to the full archive.

Continue reading

×