TeamViewer published security bulletin TV-2026-1010 this week, fixing five high-severity vulnerabilities in its Full Client and Host components. The most serious, CVE-2026-92370, is an improper access control flaw in remote sessions that can be escalated to arbitrary code execution. TeamViewer says it is not aware of public disclosure or in-the-wild exploitation, and no public exploit code is known. The fix ships in version 15.82, and the company is urging customers to update as soon as possible.

The vulnerabilities

CVEClassNotes
CVE-2026-92370Improper access control (remote session)CVSS 8.8. An authenticated remote party can alter access-control parameters to bypass restrictions the session owner configured, and can reach code execution.
CVE-2026-19743Path traversal / improper path validationLocal IPC service. A low-privileged local user can perform arbitrary file writes with elevated privileges, leading to local privilege escalation.
CVE-2026-92368Heap-based buffer overflowTriggered while processing .tvs session recording files. A size mismatch during decompression causes out-of-bounds heap writes.
CVE-2026-92369TOCTOU race conditionWindows installer rollback mechanism. Winning the race yields local privilege escalation.
CVE-2026-92371Improper path validationLinux. Reported at CVSS 7.0.

The bulletin covers TeamViewer versions prior to 15.82 plus some legacy branches.

Technical analysis

CVE-2026-92370 is the one infrastructure teams should triage first. TeamViewer sessions let the host restrict what a connected peer may do, such as file transfer, remote execution, or clipboard access. This flaw lets a connected, authenticated peer change the parameters that enforce those restrictions and perform actions the host denied. Combined with the code-execution capability reported in the bulletin, a session that was meant to be view-only or limited-scope becomes a path to running code on the host. The attacker still needs an authenticated session, so the realistic abuse cases are a compromised or malicious support technician account, a stolen session credential, or an unattended-access device whose credentials have leaked.

CVE-2026-92368 is a client-side parsing bug: opening a crafted .tvs recording could corrupt heap memory. This needs user interaction, so it is mostly a phishing or file-sharing vector, for example a “session recording” sent to a helpdesk analyst.

CVE-2026-19743 and CVE-2026-92369 are local privilege escalations. They matter after initial access: ransomware operators and intrusion sets routinely abuse remote-access tooling already present on a host, and a LPE in an installed, SYSTEM-level service is a convenient step from a low-privileged foothold to full control. CVE-2026-92371 is the Linux counterpart in path handling.

Impact

Remote-access software is a high-value target because it is deployed widely, runs with elevated privileges, and is trusted by network controls. Servers with TeamViewer Host, jump hosts, kiosks and OT-adjacent workstations are the exposures that deserve attention. None of these flaws is reported as exploited, but TeamViewer has been abused in intrusions before, so expect researchers and attackers to diff the 15.82 release quickly.

Mitigation

  1. Update all TeamViewer Full Client and Host installations to 15.82 or later on Windows, Linux and macOS. Inventory first; unmanaged and legacy installs on servers and jump boxes are the usual gaps.
  2. Audit unattended-access devices and remove TeamViewer from systems that no longer need it.
  3. Review connection logs for unexpected sessions, and rotate credentials and trusted-device lists for accounts that may be exposed.
  4. Enforce allowlisting so only approved TeamViewer binaries and configurations run, and alert on unexpected child processes spawned by the TeamViewer service.
  5. Treat .tvs recordings from untrusted sources as untrusted input until patched.

No workaround is described for the access control bypass beyond updating.

References