Like giving a house guest a view-only tour and discovering they can unlock every door
CVE-2026-92370 is an improper access control flaw in TeamViewer Full Client, Host, and related modules across Windows, Linux, and macOS. Versions prior to 15.82 (and legacy branches 15.64.x, 14.7.x, 13.2.x before their respective patches) allow a remote party in a TeamViewer session to modify access control parameters during session establishment, bypassing restrictions the host user explicitly configured — such as view-only mode, disabled file transfer, or blocked remote input. The result: actions the victim thought were locked down become available, up to and including remote code execution on the target endpoint. Affected version ranges span >=15.0, <15.82 on all platforms, plus legacy <15.64.8 (Windows 7/8), <14.7.48855, and <13.2.36230 (Win) / <13.2.153995 (Linux) / <13.2.153994 (macOS).
TeamViewer rates this HIGH at 8.8 and the CVSS vector backs it up: network-accessible, low complexity, full CIA impact. That said, the UI:R (user interaction required) metric means the victim must be in an active session with the attacker — via social engineering, tech-support pretexting, or a compromised help desk flow. This friction is real but *not exotic*: TeamViewer-based social engineering is a top-five initial access technique in BEC and tech-support scam campaigns globally. We slightly downgrade to 8.0 because no public PoC exists, no exploitation has been observed, the bypass only matters when the victim has configured restrictive permissions (many installs run defaults that grant full access anyway), and the vendor's 8.8 slightly overstates the spray-and-pray scenario. The vendor's direction is correct; the magnitude is a touch generous.
5 steps from start to impact.
Obtain victim's TeamViewer ID and session credentials
- Target has TeamViewer Full Client or Host installed and running
- Attacker obtains TeamViewer ID + password, session link, or Easy Access token
- Requires social engineering or credential compromise — not remotely exploitable by scanning
- Enterprise Tensor deployments with conditional access policies add an identity-layer gate
- Quick Support sessions require the victim to actively launch the QS module and read out the code
TeamViewer.exe / TeamViewer_Desktop.exe spawning with network connections to *.teamviewer.com). TeamViewer management console logs session source IDs.Victim accepts session with restrictive permissions configured
- Victim accepts the connection or unattended access is configured
- Host has configured restrictive permission settings that limit the remote party
- If permissions are at default (full access), the bypass adds nothing — attacker already has full control
- Attended sessions show a visible pop-up; security-conscious users may reject unexpected connections
Modify access control parameters during session handshake
- Active TeamViewer session handshake in progress
- Knowledge of TeamViewer's proprietary session negotiation protocol
- No public PoC or automated tooling exists as of 2026-10-01
- Requires reverse-engineering TeamViewer's closed-source session negotiation — not trivial for commodity attackers
Escalate to full session control
- Successful permission bypass from step 3
- All remote actions are visible on the victim's screen unless the attacker also bypasses the black-screen restriction
- EDR/XDR on the endpoint may detect post-exploitation commands
cmd.exe, powershell.exe, wscript.exe, certutil.exe). SIEM rules for file transfer activity via TeamViewer relay domains. DLP for sensitive-file exfiltration through TeamViewer's file transfer channel.Post-exploitation: data exfiltration or lateral movement
- Full interactive session from step 4
- Endpoint has credentials, sensitive data, or network adjacency to pivot
- Modern EDR (CrowdStrike, Defender for Endpoint, SentinelOne) flags credential dumping and lateral movement tooling
- Network segmentation limits pivot reach from user workstations
*.teamviewer.com) and port 5938/TCP at the firewall/proxy for all other hosts. This eliminates the attack surface entirely on hosts that don't require remote support, reducing your vulnerable population without patching. Deploy within 30 days.TeamViewer.exe or TeamViewer_Desktop.exe spawning cmd.exe, powershell.exe, wscript.exe, certutil.exe, mshta.exe, or rundll32.exe. Also alert on file writes to %TEMP% originating from TeamViewer's file transfer module. This does not prevent exploitation but detects post-exploitation activity, reducing attacker dwell time. Deploy within 30 days.- Tightening TeamViewer permission settings — This is precisely what CVE-2026-92370 bypasses. The bulletin explicitly warns that prior configuration-based mitigations do not protect against this flaw. Adding more view-only or no-transfer restrictions gives false confidence.
- Network segmentation alone — TeamViewer sessions are brokered through TeamViewer's cloud relay infrastructure over HTTPS (port 443 fallback). Standard east-west segmentation does not block these connections unless you explicitly block
*.teamviewer.comat the proxy/firewall layer. - MFA on the TeamViewer management account — Account-level MFA protects console login, not individual session establishment. A Quick Support session code or Easy Access token does not traverse the account MFA gate.
- Host-based firewall blocking port 5938 — TeamViewer falls back to ports 443 and 80 when 5938 is blocked. You must block the *domains*, not just the port, to effectively cut off relay access.
The supporting signals.
| In-the-Wild Exploitation | Not observed. TeamViewer explicitly states no evidence of active exploitation. Not listed in CISA KEV. |
|---|---|
| Proof of Concept | Not available. No public PoC found on GitHub (no repos named CVE-2026-92370), pocindex.io, ExploitDB, or Nuclei templates as of 2026-10-01. No researcher has published exploit details or tooling. |
| EPSS Score | Pending. FIRST.org EPSS model evaluation in progress — CVE was disclosed 2026-09-29, expect initial score within 7–14 days. Given the UI:R requirement and no PoC, expect EPSS in the 5th–25th percentile range. |
| KEV Status | Not listed. CISA Known Exploited Vulnerabilities catalog does not include this CVE as of 2026-10-01. |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (8.8) — Network-accessible, low complexity, no privilege on the target system, but requires user interaction (victim must be in or accept a session). Full confidentiality, integrity, and availability impact. Scope unchanged. |
| Affected Versions | Full Client & Host: >=15.0, <15.82 on Windows, Linux, macOS. Legacy: <15.64.8 (Win 7/8 only), <14.7.48855 (all platforms), <13.2.36230 (Windows), <13.2.153995 (Linux), <13.2.153994 (macOS). |
| Fixed Versions | 15.82 (current branch). Legacy: 15.64.8 (Win 7/8), 14.7.48855 (all platforms), 13.2.36230 (Win), 13.2.153995 (Linux), 13.2.153994 (macOS). |
| Installed Base / Exposure | TeamViewer reports 600,000+ enterprise customers globally. Millions of endpoints. TeamViewer traffic routes through *.teamviewer.com relay servers on port 5938/TCP (fallback 443/80) — not directly exposed on host IPs. Shodan/Censys scans are less relevant because sessions are relay-brokered, not direct-connect. |
| Disclosure Date | 2026-09-29 via TeamViewer Security Bulletin TV-2026-1010. Part of a coordinated five-CVE disclosure batch (CVE-2026-19743, -92368, -92369, -92370, -92371). |
| Researcher / Reporter | Not disclosed. TeamViewer has not credited a specific researcher or organization for this finding. No bug bounty or coordinated disclosure attribution in the bulletin. |
Sources.
- TeamViewer Security Bulletin TV-2026-1010
- BleepingComputer — TeamViewer urges users to patch severe flaws
- CybersecurityNews — Critical TeamViewer Vulnerabilities
- SecurityOnline — TeamViewer Fixes Five High-Severity Flaws
- Strix.ai — CVE-2026-92370 Analysis
- PBXScience — TeamViewer 15.82 Patch Advisory
- TheHackerWire — CVE-2026-92370 Breakdown
- PRSOL:CC — TeamViewer Patch Urgency
Why this verdict
- Social engineering gate is real but proven: The UI:R requirement means the attacker must get the victim into an active TeamViewer session — via vishing, phishing the help desk, or compromised MSP credentials. This is a meaningful gate against mass exploitation, but TeamViewer social engineering is a *mature, frequently observed* initial access technique used in ransomware (Conti, Royal, Black Basta playbooks), BEC, and tech-support scam campaigns. The friction does not drop severity below HIGH — it prevents CRITICAL.
- No PoC or exploitation observed — 0.8-point downward adjustment: As of 48 hours post-disclosure, no public exploit code exists and TeamViewer reports no wild exploitation. This meaningfully reduces urgency compared to a weaponized-on-day-zero scenario. Without a PoC, commodity attackers cannot reproduce the bypass; only researchers who independently reverse-engineer TeamViewer's session protocol pose a near-term threat.
- Permission bypass is conditional on restrictive config: The vulnerability only provides *additional* capability when the host has configured restrictive permissions (view-only, no file transfer). If the victim's TeamViewer runs default settings (which grant full access to the connecting party), the bypass is moot — the attacker already has everything. This narrows the vulnerable population to security-conscious deployments that bothered to restrict permissions, which is a smaller subset of the 600K+ customer base.
- Role multiplier: TeamViewer is primarily deployed on workstations and employee endpoints (typical role). On a workstation, successful exploitation yields single-host compromise: credential harvesting, data exfiltration, lateral movement staging. TeamViewer Host is *also* deployed on servers for unattended access (some enterprises, ~5-10% of installs) and in MSP environments where one session pivot reaches multiple client tenants — pushing toward high-value role territory. However, TeamViewer is not a canonical high-value-role component — it is not a domain controller, identity provider, hypervisor, certificate authority, or kernel-mode agent. The worst plausible blast radius (MSP pivot to multiple tenants, or server Host with domain-joined credentials) is host-level to tenant-level, not domain/fleet/supply-chain scale. This sets the floor at HIGH. The massive installed base and proven social engineering pipeline prevent any drop to MEDIUM.
- Cross-platform amplifier: The vulnerability affects Windows, Linux, *and* macOS simultaneously with the same attack technique. A single exploit works across heterogeneous fleets, widening the addressable target population and keeping the score elevated within HIGH.
Why not higher?
CRITICAL would require either active exploitation, a weaponized PoC, or a canonical high-value-role component where the blast radius is domain/fleet/supply-chain scale. TeamViewer is a remote access tool deployed primarily on endpoints — not infrastructure-defining software like Active Directory, vCenter, or a CA. The UI:R dependency means this cannot be mass-exploited without per-target social engineering interaction, fundamentally capping blast radius. There is no evidence of chaining with the four sibling CVEs (path traversal CVE-2026-19743, heap overflow CVE-2026-92368, TOCTOU CVE-2026-92369, link resolution CVE-2026-92371) to achieve a fully unauthenticated attack path.
Why not lower?
MEDIUM would ignore the massive installed base (600K+ enterprise customers, millions of endpoints), the proven and actively used social engineering pipeline for TeamViewer access, and the full CIA impact (interactive RCE) once the bypass succeeds. TeamViewer is one of the most commonly abused legitimate tools (LOTL) in ransomware and BEC campaigns — any vulnerability that lowers the bar for in-session abuse stays HIGH at minimum. The cross-platform coverage and lack of any vendor workaround reinforce this floor.
Crowdsourced verification payload.
Run this on each target Windows host where TeamViewer may be installed. No elevation required — runs as standard user. Invoke with: powershell -ExecutionPolicy Bypass -File .\Check-CVE-2026-92370.ps1. For Linux/macOS, check teamviewer --version and compare against fixed versions: 15.82 (current), 14.7.48855, 13.2.153995 (Linux), 13.2.153994 (macOS).
# Check-CVE-2026-92370.ps1
# Detects TeamViewer installations vulnerable to CVE-2026-92370
# (Remote Session Permission Bypass via Improper Access Control)
# Output: VULNERABLE / PATCHED / UNKNOWN
# Exit codes: 1 = VULNERABLE, 0 = PATCHED, 2 = UNKNOWN
$ErrorActionPreference = 'SilentlyContinue'
# Fixed versions per major branch
$fixedVersions = @{
'15' = [version]'15.82.0.0'
'14' = [version]'14.7.48855.0'
'13' = [version]'13.2.36230.0'
}
$tvVersion = $null
$tvSource = ''
# 1. Check registry locations
$regPaths = @(
'HKLM:\SOFTWARE\TeamViewer',
'HKLM:\SOFTWARE\WOW6432Node\TeamViewer',
'HKCU:\SOFTWARE\TeamViewer'
)
foreach ($rp in $regPaths) {
if (Test-Path $rp) {
$v = (Get-ItemProperty -Path $rp -Name 'Version' -ErrorAction SilentlyContinue).Version
if ($v) { $tvVersion = $v; $tvSource = "registry ($rp)"; break }
}
}
# 2. Fallback: check file version of TeamViewer.exe
if (-not $tvVersion) {
$candidates = @(
"$env:ProgramFiles\TeamViewer\TeamViewer.exe",
"${env:ProgramFiles(x86)}\TeamViewer\TeamViewer.exe",
"$env:LOCALAPPDATA\TeamViewer\TeamViewer.exe",
"$env:ProgramFiles\TeamViewer Host\TeamViewer_Host.exe"
)
foreach ($c in $candidates) {
if (Test-Path $c) {
$fi = (Get-Item $c).VersionInfo
$tvVersion = $fi.ProductVersion
$tvSource = "file ($c)"
break
}
}
}
# 3. Fallback: check running process
if (-not $tvVersion) {
$proc = Get-Process -Name 'TeamViewer','TeamViewer_Service','TeamViewer_Host' -ErrorAction SilentlyContinue | Select-Object -First 1
if ($proc) {
$tvVersion = $proc.FileVersion
$tvSource = "process ($($proc.ProcessName))"
}
}
if (-not $tvVersion) {
Write-Output 'UNKNOWN - TeamViewer not detected on this host.'
exit 2
}
try {
$clean = ($tvVersion -replace '[^0-9.]', '').TrimEnd('.')
$parsed = [version]$clean
$major = $parsed.Major.ToString()
Write-Output "Detected TeamViewer version $tvVersion (source: $tvSource)"
if ($fixedVersions.ContainsKey($major)) {
$fixed = $fixedVersions[$major]
if ($parsed -ge $fixed) {
Write-Output "PATCHED - Version $parsed >= fixed version $fixed."
exit 0
} else {
Write-Output "VULNERABLE - Version $parsed < fixed version $fixed. CVE-2026-92370 applies."
exit 1
}
} elseif ($parsed.Major -gt 15) {
Write-Output "PATCHED - Version $parsed is newer than all affected branches."
exit 0
} elseif ($parsed.Major -lt 13) {
Write-Output "UNKNOWN - Version $parsed is older than tracked branches (13/14/15). Likely EOL and vulnerable; confirm with vendor."
exit 2
} else {
Write-Output "UNKNOWN - Version $parsed detected but major branch $major not in fixed-version map."
exit 2
}
} catch {
Write-Output "UNKNOWN - Could not parse TeamViewer version string: $tvVersion"
exit 2
}