Cyber Security News

Multiple TeamViewer Vulnerabilities Enable RCE, Access Control Bypass and Privilege Escalation

TeamViewer has issued security bulletin TV-2026-1010 to address five high-severity vulnerabilities found in the TeamViewer Full Client, Host, and related services.

These vulnerabilities affect deployments on Windows, Linux, and macOS, and include issues such as remote code execution, session permission bypass, arbitrary privileged file writes, and local privilege escalation.

Multiple TeamViewer Vulnerabilities

CVE-2026-19743 – Path Traversal Enables Elevated File Writes  

This vulnerability involves improper restrictions of a pathname to a restricted directory, commonly referred to as path traversal. It affects the local IPC service in TeamViewer Full Client and Host.

A low-privileged local authenticated attacker can send crafted IPC commands to the TeamViewer service daemon, allowing them to manipulate file paths.

This could lead to arbitrary file writes with elevated permissions, potentially executing commands as NT AUTHORITY\SYSTEM on Windows or root on Linux and macOS.

According to Teamviewer, this issue affects Full Client and Host versions before 15.82. Also, it impacts older legacy branches before 15.64.8 on Windows and earlier patches in the 14.7 and 13.2 branches.

CVE-2026-92368 – Malicious Session Recordings Can Trigger RCE  

This vulnerability is a heap-based buffer overflow affecting the processing of TeamViewer .tvs session-recording files on Linux and macOS. A size mismatch during the decompression of recorded session data can lead to an out-of-bounds heap write.

An attacker must convince a user to open a malicious .tvs file through the “Play or convert recorded session” feature. Successful exploitation could enable arbitrary code execution in the current user’s context. This flaw affects TeamViewer Full Client and Host versions on Linux and macOS from 15.70 to versions before 15.82.

CVE-2026-92369 – Installer Rollback Race Condition  

This vulnerability involves a time-of-check-to-time-of-use race condition in the TeamViewer Windows installer rollback mechanism. During an installation or update rollback, the installer stores backup files in a user-writable temporary directory before an elevated installer process restores them.

A local low-privileged attacker who successfully exploits the race condition may replace these files, allowing the elevated process to restore attacker-controlled content, which could lead to privilege escalation to NT AUTHORITY\SYSTEM.

This issue affects TeamViewer Full Client and Host versions before 15.82 on Windows, including the impacted 15.64, 14.7, and 13.2 maintenance branches.

CVE-2026-92370 – Access-Control Bypass May Lead to RCE  

This is the highest-rated vulnerability in the bulletin, with a CVSS score of 8.8. It involves improper access control that affects TeamViewer Full Client, Host, and related modules across Windows, Linux, and macOS.

An authenticated remote attacker could modify access control parameters during session establishment and bypass user-configured restrictions for remote-session features.

This could allow actions the target user specifically denied, potentially resulting in remote code execution on the victim’s system. All Full Client and Host versions before 15.82 are affected, along with vulnerable legacy releases in the 15.64, 14.7, and 13.2 branches.

CVE-2026-92371 – Linux Cloud Recording Privilege Escalation  

This vulnerability impacts the Cloud Session Recording functionality in TeamViewer Full Client and Host for Linux. It involves improper link resolution and a race condition between path validation and file access.

A local authenticated attacker may exploit this condition to redirect privileged file operations to unintended locations. The vulnerability could allow local privilege escalation, depending on the attacker’s ability to influence targeted files and win the race condition. This issue affects Linux versions from 15.0 through releases earlier than 15.82.

Organizations should prioritize deploying TeamViewer version 15.82 across all managed endpoints. Teams using older operating systems or specific TeamViewer releases should install the corresponding maintenance updates: 15.64.8 for Windows 7 and Windows 8, 14.7.48855 for version 14.7 deployments, and the relevant patched versions for 13.2.

Security teams should restrict local access on systems running TeamViewer, limit who can initiate or accept remote sessions, verify remote access permissions after patching, and treat unsolicited .tvs files as untrusted content.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

4 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago