Sceawere

Vulnerability Detail

CVE-2026-92370UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TeamViewer Improper Access Control Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
9h ago
Vendor
TeamViewer
Product
Full Client
Attack Type
CWE-284 Improper Access Control
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-29T16:17:15.033Z",
  "pubdate": "2026-09-29T16:17:15.033Z",
  "executiveSummary": "This vulnerability involves an improper access control flaw within the TeamViewer Full Client and Host modules across Windows, Linux, and macOS platforms. The security defect allows an authenticated remote attacker to circumvent locally configured permission settings during the initial session establishment phase.\nBy manipulating access control parameters, an attacker can execute restricted features that were explicitly disabled by the victim's local policy configuration. This bypass directly undermines the integrity of the remote access security model, facilitating unauthorized administrative actions.\nThe risk implication is critical, as successful exploitation enables an attacker to transcend the established security boundaries of the application, leading to unauthorized system manipulation. In worst-case scenarios, the exploit allows for remote code execution (RCE) on the target host, granting the attacker control over the underlying system. The vulnerability requires the attacker to be authenticated to initiate the connection; however, no elevated local privileges are necessary to trigger the permission override once the session is active. Organizations relying on TeamViewer for secure remote support must treat this as a high-priority risk, as it effectively nullifies granular user-defined security restrictions.",
  "technicalDetails": "The vulnerability resides in the handshake and authorization logic governing session establishment within TeamViewer Full Client and Host modules. The root cause is the application's failure to enforce server-side or client-side integrity checks on session access control parameters transmitted during the connection phase. Specifically, the client fails to validate that the requested feature permissions align with the pre-configured security policy stored on the target system.\nThe exploitation flow begins when an attacker, possessing valid authentication credentials or session access tokens, initiates a connection to the target TeamViewer instance. During the initial negotiation of the remote control session, the attacker deliberately modifies the request headers or packet payloads associated with feature permission settings. By injecting or altering these parameters, the attacker forces the TeamViewer host service to ignore the 'restricted' flags configured by the legitimate user.\nOnce the session is established with the modified parameters, the victim's predefined granular restrictions—such as disabling file transfer, remote shell, or system setting access—are rendered ineffective. The application improperly trusts the attacker-supplied permission set rather than re-validating the requested features against the actual local Access Control List (ACL) or the local configuration file stored on the host system.\nThis behavior facilitates a privilege escalation equivalent, where the attacker bypasses intended functional boundaries. Because the remote host processes these instructions as legitimate authorized requests, the attacker can leverage elevated functionality that should have been prohibited. This scenario effectively weaponizes the remote management protocol. If the application is running with administrative privileges, the ability to execute unauthorized commands or access sensitive files can lead to remote code execution (RCE). Post-exploitation impact includes full system compromise, exfiltration of sensitive data, or the deployment of arbitrary malicious payloads, as the attacker effectively bypasses the application's internal security checks to interact with the OS API directly."
}
CVE-2026-92370: TeamViewer Improper Access Control Bypass (HIGH Severity, CVSS: 8.8) | Sceawere