TeamViewer has released security updates addressing five vulnerabilities across its Full Client and Host products on Windows, Linux and macOS, with severity ratings reaching CVSS 8.8 High. The flaws affect TeamViewer Remote, Tensor and ONE, and include local privilege escalation, arbitrary file writes, malicious session-recording execution, and, most importantly, a remote session access-control bypass that could allow an attacker to perform actions the user had explicitly configured TeamViewer to deny.

The highest-rated issue, CVE-2026-92370, is the one organizations should pay particular attention to. TeamViewer says an authenticated remote attacker can manipulate access-control parameters during session establishment and bypass restrictions configured by the victim. Depending on the permissions bypassed, this could allow actions that were deliberately disabled and may ultimately result in remote code execution on the target system. The vulnerability affects TeamViewer Full Client, Host and related modules on Windows, Linux and macOS prior to version 15.82, with supported fixes also available for several legacy branches.

The important nuance is that this is not an unauthenticated Internet-wide RCE. The attacker still needs to establish an authenticated TeamViewer session and requires user interaction as reflected in TeamViewer’s CVSS vector. That substantially narrows the attack surface compared with a pre-authentication remote exploit. However, once a remote session has been accepted, the victim’s access-control settings are supposed to define the limits of what that remote user can do. A vulnerability that lets the attacker bypass those limits undermines the security boundary users rely on after the connection is established.

That makes CVE-2026-92370 particularly relevant in environments where TeamViewer is used for vendor support, help-desk operations, managed services, or access to sensitive systems. An organization may intentionally permit screen viewing while denying file transfer, command execution, clipboard use or other high-risk functions. If those restrictions can be bypassed, the attacker may gain substantially more capability than the user or administrator intended to grant.

The broader lesson is that authentication and authorization are different security controls. A remote user may be legitimately authenticated while still being authorized to perform only a narrow set of actions. If the authorization layer fails after authentication succeeds, valid credentials or an approved session can become the starting point for abuse.

The second significant issue, CVE-2026-19743, is a path-traversal vulnerability in TeamViewer’s local IPC service. On Windows, Linux and macOS, a low-privileged authenticated local user can send crafted IPC commands that manipulate file paths and perform arbitrary file writes using the elevated privileges of the TeamViewer service daemon. On Windows that can mean NT AUTHORITY\SYSTEM, while on Linux or macOS it can mean root-level privileges.

Arbitrary privileged file write is a dangerous primitive because attackers can often turn it into local privilege escalation. Depending on the operating system and writable target, an attacker may be able to replace configuration files, scripts, libraries, scheduled-task content, service files or other resources subsequently processed by a privileged component.

This issue again requires local low-privileged access, so it is not the initial breach vector most organizations fear. However, in a multi-stage attack it can become extremely useful after phishing, malware execution or credential theft gives the attacker an ordinary local foothold.

The practical attack progression could become:

low-privileged compromise → abuse TeamViewer IPC service → privileged file write → SYSTEM/root execution → persistence or credential theft

That is why local privilege-escalation vulnerabilities in trusted remote-management software deserve attention even when they cannot be exploited directly from the Internet.

Another flaw, CVE-2026-92369, affects the Windows installer rollback mechanism. TeamViewer says a time-of-check/time-of-use race condition allows a low-privileged local attacker to replace rollback backup files stored in a user-writable temporary directory before the elevated installer restores them. If the timing succeeds during installation or update rollback, the attacker may escalate privileges to NT AUTHORITY\SYSTEM.

Race-condition vulnerabilities are generally harder to exploit reliably than straightforward file-permission errors because the attacker must win a timing window. TeamViewer reflects that difficulty in the lower CVSS score of 7.3 High and the requirement for user interaction. But successful exploitation would still cross the most important Windows privilege boundary: ordinary user to SYSTEM.

The vulnerability also highlights an often-overlooked security area: software installers and update processes. Installers routinely execute with elevated privileges and manipulate files in temporary locations. Any gap between validating a file and later using it creates an opportunity for an attacker to substitute content.

The security model should therefore avoid trusting user-writable temporary paths across privilege boundaries. If privileged software validates one file and later reopens it by pathname, a lower-privileged process may be able to replace or redirect that pathname in the meantime.

TeamViewer also patched CVE-2026-92371, a Linux-specific issue in Cloud Session Recording. A race condition and improper link resolution can allow a low-privileged local attacker to redirect privileged file operations toward unintended filesystem locations. The issue affects Linux TeamViewer Full Client and Host releases from version 15.0 up to, but not including, 15.82 and is rated 7.0 High.

Like the Windows rollback vulnerability, this is another example of how path validation can fail if the object being validated can change between the security check and the privileged file operation. Symlinks and other filesystem redirection mechanisms become particularly dangerous when a privileged process operates on paths influenced by an unprivileged user.

The fifth issue, CVE-2026-92368, affects TeamViewer session-recording playback on Linux and macOS. TeamViewer says a heap-based buffer overflow occurs while decompressing specially crafted .tvs session-recording files because of a size mismatch in the recorded data. An attacker who convinces a user to open the malicious recording through TeamViewer’s “Play or convert recorded session…” feature may achieve arbitrary code execution with the privileges of that user.

This vulnerability is different from the others because exploitation depends on a malicious file rather than local access or a live TeamViewer session.

The basic attack chain is familiar:

attacker prepares malicious .tvs file → victim receives file through email, messaging or another channel → victim opens it in TeamViewer → decompression triggers heap corruption → attacker-controlled code executes

The requirement for user interaction lowers the likelihood of opportunistic exploitation, but organizations should remember that recorded TeamViewer sessions may look inherently trustworthy to IT staff. A malicious file can be disguised as a support recording, diagnostic capture or evidence from a previous session.

The vulnerability also demonstrates why security teams should not automatically trust proprietary file formats simply because they belong to an enterprise application. File parsers remain a large and recurring attack surface, particularly where complex compression, media, document or session data is involved.

The common theme across several of these flaws is privilege concentration.

TeamViewer is intentionally powerful software. Its purpose is to allow remote control, file manipulation, support, automation and administration. Its background services may therefore run with elevated privileges and sit in a highly trusted position on the endpoint.

That means vulnerabilities inside TeamViewer can have disproportionate consequences compared with flaws in ordinary desktop software.

Attackers frequently look for security, management and remote-access software precisely because those tools already possess privileges the attacker wants.

This is why organizations should treat remote-management platforms as high-value administrative infrastructure, not ordinary productivity applications.

TeamViewer should be inventoried centrally.

Access should be limited.

Unattended access should be enabled only where genuinely required.

MFA should be enforced.

Session permissions should follow least privilege.

Connection logs should be centrally reviewed.

And software updates should be deployed with the same urgency given to VPN gateways, RMM tools and privileged-access platforms.

The exposure is especially important in managed-service environments. An MSP or IT department may have TeamViewer deployed across hundreds or thousands of endpoints, making a vulnerable client a broadly distributed attack surface.

A single workstation compromise could potentially be combined with local privilege escalation.

A malicious remote connection could exploit authorization weaknesses.

And social engineering could weaponize malicious TeamViewer session files against support personnel.

The vulnerabilities therefore should not be evaluated independently from the way the product is actually deployed.

An organization using TeamViewer occasionally on a handful of locked-down machines faces a different risk from an MSP relying on unattended TeamViewer Hosts across thousands of customer endpoints.

TeamViewer says all five vulnerabilities have been fixed in version 15.82, and it has also released patched builds for supported maintenance and legacy versions. For the 15.x main branch, anything below 15.82 should be considered affected by at least some of the vulnerabilities described in this bulletin.

TeamViewer has also published fixed versions for older deployments, including updated 15.64 builds for Windows 7 and 8 environments and patched 14.7 and 13.2 releases across supported operating systems. Organizations using legacy versions should therefore consult the vendor bulletin rather than assuming migration to the newest branch is their only immediate remediation path.

At the same time, long-term reliance on legacy remote-access software should be treated as technical debt.

Security patches may continue to appear for selected branches, but older operating systems and remote-management stacks inevitably accumulate compatibility and security constraints. Where possible, organizations should move toward fully supported platforms rather than turning emergency legacy patching into an annual tradition.

The good news is that TeamViewer says it is not aware of active exploitation in the wild or previous public disclosure of these vulnerabilities at the time of its September 29 advisory.

That gives defenders a valuable window.

The patches exist before widespread exploitation has been reported.

Organizations should use that window rather than waiting for proof-of-concept code, scanning activity or ransomware operators to turn the vulnerabilities into tomorrow’s incident-response problem.

The appropriate response is straightforward:

identify TeamViewer installations → determine version and operating system → prioritize Internet-facing, unattended and privileged deployments → update to 15.82 or the appropriate patched legacy build → verify the updated version → review remote-access permissions and logs

Security teams should also examine whether TeamViewer is installed where it is no longer required.

Remote-access products have a habit of remaining on endpoints years after the original support requirement disappears.

Every unnecessary installation adds another privileged service and another route an attacker may eventually try to abuse.

Organizations should additionally review connection histories for suspicious TeamViewer sessions, particularly unusual remote identities, unexpected access times, systems that normally do not receive support sessions, and connections followed by new process execution or privilege changes.

There is currently no indication these new flaws are already being exploited, so retrospective hunting should not be presented as evidence that compromise is expected.

It is simply sensible hygiene for software with remote-control capability.

The broader lesson from this TeamViewer advisory is that remote-access software effectively creates an administrative doorway into the endpoint.

Security depends not only on deciding who may open that doorway, but also on controlling what they may do once inside and ensuring the software operating the doorway itself cannot be abused to gain additional privileges.

The five vulnerabilities expose weaknesses at several different boundaries:

remote authentication → authorization

local user → SYSTEM/root

untrusted file → code execution

validated path → privileged file operation

That is why the bulletin deserves more attention than a normal collection of desktop-software CVEs.

TeamViewer sits at a privileged point between users, administrators and endpoints.

When software occupying that position receives multiple high-severity security fixes, patching should not wait for attackers to provide practical motivation.


Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]

Source: TeamViewer urges users to patch severe flaws “as soon as possible” via Bleeping Computer — published 30 Sep 2026.