TeamViewer has patched a critical access-control bypass vulnerability in its Full Client and Host software that could allow unauthorized remote code execution, alongside four additional flaws disclosed in the same advisory.
CVE-2026-92370 Bypasses Remote-Session Access Controls
The primary flaw, CVE-2026-92370, is an improper remote-session access-control bypass affecting TeamViewer Full Client and Host across Windows, Linux, and macOS. TeamViewer’s advisory describes the issue as capable of enabling unauthorized remote code execution, making it the most severe of the five vulnerabilities addressed in the release. TeamViewer said it has no evidence that the flaw has been publicly disclosed or actively exploited, but still characterized the issues as high-severity and warranting immediate patching rather than routine update scheduling.
The access-control bypass specifically concerns how TeamViewer verifies that a party connecting to a remote session is actually authorized to do so. An improper check at that stage can allow a connection to be established, or elevated, in ways the software’s permission model was designed to prevent, which is why TeamViewer’s advisory ties the flaw directly to the possibility of unauthorized remote code execution rather than a more limited information-disclosure outcome.
Four Secondary Flaws Enable Local Privilege Escalation to SYSTEM or Root
The remaining four vulnerabilities — a path traversal bug tracked as CVE-2026-19743, a heap-based buffer overflow identified as CVE-2026-92368, a time-of-check/time-of-use race condition cataloged as CVE-2026-92369, and an improper path-validation flaw designated CVE-2026-92371 — allow a local attacker to achieve code execution with the privileges of the currently logged-in user, or to escalate further to SYSTEM-level access on Windows or root-level access on Linux and macOS.
All Three Platforms Covered by a Single Fixed Release
TeamViewer published its advisory and the patched version 15.82 on September 30, covering all three supported operating systems, and the company extended the fix to both its current release and legacy maintenance branches so that customers on older supported versions are also covered. No workarounds have been published for any of the five flaws, meaning the patched release is the only remediation path TeamViewer has made available.
Combining the Access Bypass With Local Escalation Creates a Realistic Attack Chain
Because CVE-2026-92370 operates at the remote-session layer while the other four flaws operate locally once an attacker already has some foothold on a machine, the five vulnerabilities disclosed together describe a plausible chain rather than five unrelated bugs: an attacker who first breaks into a session through the access-control bypass could then use one of the local privilege-escalation issues to move from ordinary user access to full administrative control of the host.
Why a Trusted Remote-Access Tool Raises the Stakes of This Bypass
TeamViewer’s remote-access software is deployed broadly across both consumer support scenarios and enterprise IT help-desk environments, and that ubiquity is precisely what makes an access-control bypass in the platform consequential beyond the technical severity score alone. Remote-access tools occupy a privileged position in most environments: they are explicitly trusted to grant administrative-level control to a remote party, and security teams often grant them broad exceptions in endpoint-protection and network-monitoring policies because blocking normal TeamViewer traffic would break legitimate IT support workflows. An attacker who successfully exploits an access-control bypass in that kind of tool inherits the trust already extended to it, which can make malicious activity harder to distinguish from a routine support session.
TeamViewer’s Batched Release Covers Five Distinct Vulnerability Classes
That dynamic is why security researchers have consistently flagged remote-monitoring-and-management software as a high-value target for both initial access and privilege escalation in recent years: compromising a tool organizations already trust and already permit through their defenses is frequently more efficient for an attacker than finding a novel way around those defenses in the first place. TeamViewer’s own assessment that it has no evidence of active exploitation or public disclosure is some reassurance, but it does not change the underlying calculus for defenders — once an advisory and CVE identifiers are public, the technical detail needed to reverse-engineer a working exploit becomes available to anyone motivated to look for it. Organizations running TeamViewer Full Client or Host should treat the update to version 15.82 as time-sensitive rather than discretionary, particularly in environments where the software is permitted to run with elevated privileges by default.
The decision to patch all five flaws in a single coordinated release, rather than issuing them as they were individually confirmed, also reflects a common vendor practice of batching related findings so defenders can apply one update instead of tracking several partial fixes. For IT teams managing TeamViewer across a large device fleet, that batching simplifies the operational task of remediation to a single version check, even though the underlying vulnerabilities span distinct technical categories — an access-control bypass, a path traversal bug, a heap overflow, a race condition, and a path-validation flaw — that would ordinarily be assessed and prioritized separately.
