# Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371, CVE-2026-19743)

> TeamViewer security bulletin TV-2026-1010 (29 Sep 2026) fixes five high-severity flaws in the Full Client and Host, led by CVE-2026-92370 (CVSS 8.8), a remote session access-control bypass that can lead to remote code execution. The other four are local privilege-escalation or memory-corruption bugs. All are fixed in version 15.82, and TeamViewer is not aware of public disclosure or active exploitation.

- **Published:** 2026-10-02T00:00:00Z
- **Last reviewed:** 2026-10-02T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2905
- **ID:** TL-2026-2905
- **Severity:** HIGH (CVSS 8.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 12 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-92370, CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371

## Description

TeamViewer published security bulletin TV-2026-1010 on 29 September 2026 (no later update). It covers five CVEs in the TeamViewer Full Client and Host. Per the bulletin, the researchers who reported them are unnamed and were credited generically under coordinated vulnerability disclosure. Product-line coverage in the press names TeamViewer Remote, Tensor and ONE. BleepingComputer covered the bulletin on 30 September and Truesec summarised it on 2 October 2026. All five are fixed in 15.82, and TeamViewer urges users to update as soon as possible.

CVE-2026-92370 (CVSS 3.1 8.8, AV:N/AC:L/PR:N/UI:R, CWE-284) is the most serious. It is an improper access control flaw in the Full Client, Host and related modules on Windows, Linux and macOS. A remote attacker can bypass user-configured permission settings during session establishment. By modifying access-control parameters for restricted features, the attacker can perform actions the victim's configuration explicitly denies. Truesec and BleepingComputer describe the outcome as unauthorized actions and remote code execution on the targeted system. Affected versions are everything before 15.82, plus the legacy branches 15.64, 14.7 and 13.2.

CVE-2026-19743 (CVSS 7.8, AV:L/AC:L/PR:L/UI:N, CWE-22) is improper path validation (path traversal) in the local IPC service of the Full Client and Host on Windows, Linux and macOS. A local low-privileged user can send crafted IPC commands to the service and manipulate file paths. This gives arbitrary file writes with elevated privileges (NT AUTHORITY\SYSTEM or root), i.e. local privilege escalation. Versions before 15.82 are affected, as are legacy branches 15.64, 14.7 and 13.2 (Windows/Linux).

CVE-2026-92368 (CVSS 7.8, AV:L/AC:L/PR:L/UI:N, CWE-122) is a heap-based buffer overflow in the processing of .tvs session recording files on Linux and macOS only, in versions 15.70 up to but not including 15.82. A size mismatch during decompression can cause out-of-bounds heap writes. Media coverage describes the impact as local code execution with the current user's privileges, with some outlets also citing escalation to SYSTEM/root.

CVE-2026-92369 (CVSS 7.3, AV:L/AC:L/PR:L/UI:R, CWE-367) is a TOCTOU race condition in the Windows installer rollback mechanism. A low-privileged attacker can replace rollback backup files in a user-writable temporary directory before the elevated installer restores them, which gives privilege escalation. Versions before 15.82 on Windows are affected, plus legacy branches 15.64, 14.7 and 13.2.

CVE-2026-92371 (CVSS 7.0, AV:L/AC:H/PR:L/UI:N, CWE-59) is an improper path validation / link resolution flaw in the Cloud Session Recording functionality, Linux only, in versions 15.0 up to but not including 15.82. A race between path validation and file access lets a local authenticated attacker cause privileged file operations in unintended locations, which is local privilege escalation to root.

TeamViewer states it is not aware of any public disclosure or active exploitation in the wild. No source reports public exploit code, attribution or network IOCs, and the vendor bulletin publishes no detection guidance. Context: TeamViewer is widely deployed remote-access software that has previously been abused by threat actors and was itself breached (a 2016 intrusion linked to Chinese actors using Winnti malware, disclosed in May 2019, and a 2024 intrusion attributed to Midnight Blizzard / APT29). Defenders should prioritise patching, inventory legacy branches, and monitor for anomalous TeamViewer sessions and permission changes.

## MITRE ATT&CK

- T1219 Remote Access Tools
- T1203 Exploitation for Client Execution
- T1211 Exploitation for Stealth
- T1133 External Remote Services

## Sources

- [Multiple High-Severity Vulnerabilities in TeamViewer (Truesec)](https://www.truesec.com/hub/blog/multiple-high-severity-vulnerabilities-in-teamviewer)
- [TeamViewer Security Bulletin TV-2026-1010](https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/)
- [TeamViewer urges users to patch severe flaws as soon as possible (BleepingComputer)](https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible/)
- [TeamViewer patches five critical flaws, urges immediate update to 15.82](https://pasqualepillitteri.it/en/news/19484/teamviewer-patches-critical-flaws-cve)
- [TeamViewer: five vulnerabilities, immediate update (secnews.gr)](https://www.secnews.gr/en/737043/teamviewer-pente-eupatheies-ameso-update/)
- [CVE Record CVE-2026-92370](https://www.cve.org/CVERecord?id=CVE-2026-92370)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2905
