TeamViewer fixes five vulnerabilities, including a remote session access-control bypass: update Full Client and Host to 15.82
EditorialBy TrustList Editorial
TeamViewer’s bulletin TV-2026-1010 of 29 September 2026 fixes five flaws in Full Client and Host, rated up to CVSS 8.8, one a session access-control bypass that could allow code execution. Update to 15.82 or a fixed maintenance release.
- Germany
- Cybersecurity
- Remote Access
- Remote Desktop Software
- +2 more
About TeamViewer fixes five vulnerabilities, including a remote session access-control bypass: update Full Client and Host to 15.82
TeamViewer fixes five vulnerabilities, including a remote session access-control bypass: update Full Client and Host to 15.82
29 September 2026 — TeamViewer published security bulletin TV-2026-1010 on 29 September 2026, fixing five vulnerabilities in TeamViewer Full Client and Host and related services: CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370 and CVE-2026-92371. The company rates the bulletin "Important", with CVSS scores up to 8.8, and "strongly recommends that all users update to the latest available version as soon as possible". Canada's Cyber Centre repeated the advisory the same day.
The five flaws
- Remote session access-control bypass (CVSS 8.8): in Full Client, Host and related modules on Windows, Linux and macOS, an authenticated remote attacker can bypass the permission settings a user configured during session establishment, which TeamViewer says could lead to remote code execution.
- Heap-based buffer overflow in session-recording playback (7.8): on Linux and macOS, from 15.70 to before 15.82, a crafted .tvs recording file can cause out-of-bounds writes if a user is persuaded to open it.
- Path traversal in the local IPC service (7.8): on all three platforms, a low-privileged local user can write arbitrary files with SYSTEM or root privileges.
- Race condition in the Windows installer rollback (7.3): a local low-privileged attacker can replace rollback files and escalate privileges.
- Improper link resolution in cloud session recording: a further local privilege escalation.
Which versions to install
The fixes are in version 15.82. For customers on legacy or maintenance lines, the bulletin lists fixed builds on the 15.64 (Windows), 14.7 and 13.2 lines, depending on platform. The bulletin names TeamViewer Remote, Tensor and TeamViewer ONE among the affected products.
Why it matters
TeamViewer is widely used by IT support teams and managed-service providers to reach customer machines, so an unpatched client can be a route into many networks at once. The most serious flaw needs an authenticated session, and the recording flaw needs a user to open a crafted file. The local escalations matter most on shared or multi-user machines.
What to do
- Update every TeamViewer Full Client and Host to 15.82, or to the fixed build on your maintenance line; push it through your software-deployment tool rather than waiting for auto-update.
- Tell support staff not to open session recordings (.tvs files) from outside the organisation until clients are updated.
- MSPs should check the version on unattended hosts at customer sites, which are easy to miss.
Sources
- TeamViewer Trust Center: security bulletin TV-2026-1010 — 29 September 2026
- Canadian Centre for Cyber Security: TeamViewer security advisory (AV26-977) — 29 September 2026
Categories & features
- Germany
- Cybersecurity
- Remote Access
- Remote Desktop Software
- Vulnerability Management
- Patch Management
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More GermanyThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.