Vulnerability
Published 2026-09-29
Verified 2026-09-30

TeamViewer TV-2026-1010 (29 Sep): CVE-2026-92370 session access-control bypass (CVSS 8.8) + 4 High client/host flaws; fix 15.82

TeamViewer security bulletin TV-2026-1010 (29 September 2026; Important; CVSS up to 8.8 High) patches five flaws in TeamViewer Full Client, Host and related services across TeamViewer Remote / Tensor / ONE. Highest: CVE-2026-92370 (CVSS 3.1 8.8) — improper access control lets a remote attacker on the session path bypass user-configured permission settings during session establishment and perform denied actions that may lead to remote code execution (Windows/Linux/macOS). Also: CVE-2026-19743 (7.8) local IPC path validation → arbitrary file write as SYSTEM/root (Win/Linux/macOS); CVE-2026-92368 (7.8) heap overflow in .tvs session-recording playback (Linux/macOS); CVE-2026-92369 (7.3) Windows installer rollback TOCTOU → SYSTEM; CVE-2026-92371 (7.0) Linux Cloud Session Recording path race. Fixed in TeamViewer Clients 15.82 and supported maintenance/legacy trains. Vendor: no public exploit code or in-the-wild exploitation known. Primary: TeamViewer TV-2026-1010; wire: BleepingComputer 30 Sep.

Product
TeamViewer Full Client / Host (Remote, Tensor, ONE)
Versions
Affected: Full Client and Host prior to 15.82 (platform scope varies by CVE — 92370/19743 Win+Linux+macOS; 92368 Linux+macOS; 92369 Windows; 92371 Linux CSR). Fixed: TeamViewer Clients 15.82 and supported maintenance/legacy releases per bulletin.
CVSS
/ 7.8 / 7.8 / 7.3 / 7.0 (CVSS 3.1 High: 92370, 19743, 92368, 92369, 92371)
Exploited in Australia?
unknown
Patch to
Update TeamViewer Full Client/Host to 15.82 (or the supported maintenance/legacy build named in TV-2026-1010). Prioritise attended and unattended Host endpoints; confirm managed fleets report 15.82+. No evidence of active exploitation cited by TeamViewer.

Primary: TeamViewer — TV-2026-1010 security update (29 Sep 2026) · Vendor: TeamViewer — security bulletins · CVE: CVE-2026-92370, CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371 · BleepingComputer — TeamViewer urges ASAP patch (30 Sep 2026)

vulnerabilities identity network