TeamViewer has fixed five high-severity vulnerabilities in its Full Client and Host software for Windows, Linux and macOS. The most serious lets a remote attacker override the permission settings a user has chosen for a remote session, and the rest open paths to SYSTEM or root on a machine where an attacker already has a foothold. Versions before 15.82 are affected, and the company's own security bulletin TV-2026-1010 carries the fix details.
The CVE records, filed by TeamViewer's product security team, went public on 29 September 2026. Peru's National Digital Security Centre (CNSD) flagged the set to public bodies and companies in its integrated digital security alert No. 190-2026 on 2 October. CISA's assessment attached to each record lists no known exploitation for any of the five as of 30 September.
The worst bug undoes the user's own restrictions
TeamViewer lets the person accepting a session limit what the other side can do. CVE-2026-92370 (CVSS 8.8) is an improper access control flaw in exactly that mechanism. According to the CVE record, an authenticated remote attacker can modify the access control parameters for restricted features while the session is being established, and then perform actions the victim's configuration explicitly denied. TeamViewer says this may result in unauthorized actions and could potentially lead to remote code execution on the target system.
Four more need a foothold or a booby-trapped file
The remaining four, in order of severity:
- CVE-2026-19743 (CVSS 7.8), all three platforms: improper path validation in the local IPC service. A low-privileged local user can send crafted IPC commands to the service and write arbitrary files with SYSTEM or root privileges, a local privilege escalation.
- CVE-2026-92368 (CVSS 7.8), Linux and macOS: a heap-based buffer overflow in the handling of .tvs session recording files. If a user opens a crafted recording through the "Play or convert recorded session" feature, an attacker may run code with that user's privileges.
- CVE-2026-92369 (CVSS 7.3), Windows: a race condition in the installer's rollback mechanism. A local low-privileged attacker can replace rollback backup files kept in a user-writable temporary directory before an elevated installer restores them, reaching SYSTEM. TeamViewer notes it requires winning the race and a rollback during an install or update.
- CVE-2026-92371 (CVSS 7.0), Linux: improper path validation in the Cloud Session Recording feature. By exploiting a race between the path check and the file access, a local authenticated attacker may cause privileged file operations in unintended locations.
Three of the five are local privilege escalation bugs. On their own they do not let anyone in, but they matter to whoever already has a low-privileged account on a machine. Remote access software is also a favourite of intruders precisely because it is trusted and already installed, and recent intrusions have seen criminals deliberately plant legitimate remote admin tools on victim networks.
Move to 15.82, or the patched legacy builds
Per CNSD's summary of the bulletin:
- Update TeamViewer to 15.82, or the corrected release for your operating system.
- Machines that cannot run the current release should take the maintenance updates, including 15.64.8 for Windows 7 and 8 and the fixed builds of the 14.7 and 13.2 branches.
- Inventory every Full Client, Host and related module across managed endpoints, since unattended Host installs are easy to forget.
- Do not open .tvs session recordings from unknown or unsolicited sources.
- After updating, re-check session permission settings and limit who is allowed to start or accept remote sessions.
None of these flaws is known to be exploited, which makes this the cheap moment to patch. The headline bug is a reminder that a permission setting is only as strong as the code that enforces it, and on a tool built to hand over control of a computer, that code deserves to be current.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.