Skip to content
TrustList
News

TeamViewer fixes five vulnerabilities, including a remote session access-control bypass: update Full Client and Host to 15.82

Editorial

By TrustList Editorial

TeamViewer’s bulletin TV-2026-1010 of 29 September 2026 fixes five flaws in Full Client and Host, rated up to CVSS 8.8, one a session access-control bypass that could allow code execution. Update to 15.82 or a fixed maintenance release.

About TeamViewer fixes five vulnerabilities, including a remote session access-control bypass: update Full Client and Host to 15.82

TeamViewer fixes five vulnerabilities, including a remote session access-control bypass: update Full Client and Host to 15.82

29 September 2026 — TeamViewer published security bulletin TV-2026-1010 on 29 September 2026, fixing five vulnerabilities in TeamViewer Full Client and Host and related services: CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92370 and CVE-2026-92371. The company rates the bulletin "Important", with CVSS scores up to 8.8, and "strongly recommends that all users update to the latest available version as soon as possible". Canada's Cyber Centre repeated the advisory the same day.

The five flaws

  • Remote session access-control bypass (CVSS 8.8): in Full Client, Host and related modules on Windows, Linux and macOS, an authenticated remote attacker can bypass the permission settings a user configured during session establishment, which TeamViewer says could lead to remote code execution.
  • Heap-based buffer overflow in session-recording playback (7.8): on Linux and macOS, from 15.70 to before 15.82, a crafted .tvs recording file can cause out-of-bounds writes if a user is persuaded to open it.
  • Path traversal in the local IPC service (7.8): on all three platforms, a low-privileged local user can write arbitrary files with SYSTEM or root privileges.
  • Race condition in the Windows installer rollback (7.3): a local low-privileged attacker can replace rollback files and escalate privileges.
  • Improper link resolution in cloud session recording: a further local privilege escalation.

Which versions to install

The fixes are in version 15.82. For customers on legacy or maintenance lines, the bulletin lists fixed builds on the 15.64 (Windows), 14.7 and 13.2 lines, depending on platform. The bulletin names TeamViewer Remote, Tensor and TeamViewer ONE among the affected products.

Why it matters

TeamViewer is widely used by IT support teams and managed-service providers to reach customer machines, so an unpatched client can be a route into many networks at once. The most serious flaw needs an authenticated session, and the recording flaw needs a user to open a crafted file. The local escalations matter most on shared or multi-user machines.

What to do

  • Update every TeamViewer Full Client and Host to 15.82, or to the fixed build on your maintenance line; push it through your software-deployment tool rather than waiting for auto-update.
  • Tell support staff not to open session recordings (.tvs files) from outside the organisation until clients are updated.
  • MSPs should check the version on unattended hosts at customer sites, which are easy to miss.

Sources

Categories & features