TeamViewer patches five flaws, update to version 15.82

Published

TeamViewer has fixed five high-severity vulnerabilities in its Full Client and Host software for Windows, Linux and macOS. The most serious lets a remote attacker override the permission settings a user has chosen for a remote session, and the rest open paths to SYSTEM or root on a machine where an attacker already has a foothold. Versions before 15.82 are affected, and the company's own security bulletin TV-2026-1010 carries the fix details.

The CVE records, filed by TeamViewer's product security team, went public on 29 September 2026. Peru's National Digital Security Centre (CNSD) flagged the set to public bodies and companies in its integrated digital security alert No. 190-2026 on 2 October. CISA's assessment attached to each record lists no known exploitation for any of the five as of 30 September.

The worst bug undoes the user's own restrictions

TeamViewer lets the person accepting a session limit what the other side can do. CVE-2026-92370 (CVSS 8.8) is an improper access control flaw in exactly that mechanism. According to the CVE record, an authenticated remote attacker can modify the access control parameters for restricted features while the session is being established, and then perform actions the victim's configuration explicitly denied. TeamViewer says this may result in unauthorized actions and could potentially lead to remote code execution on the target system.

Four more need a foothold or a booby-trapped file

The remaining four, in order of severity:

Three of the five are local privilege escalation bugs. On their own they do not let anyone in, but they matter to whoever already has a low-privileged account on a machine. Remote access software is also a favourite of intruders precisely because it is trusted and already installed, and recent intrusions have seen criminals deliberately plant legitimate remote admin tools on victim networks.

Move to 15.82, or the patched legacy builds

Per CNSD's summary of the bulletin:

None of these flaws is known to be exploited, which makes this the cheap moment to patch. The headline bug is a reminder that a permission setting is only as strong as the code that enforces it, and on a tool built to hand over control of a computer, that code deserves to be current.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions