OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-92368

HIGH · CVSS 7.8 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A heap-based buffer overflow vulnerability exists in TeamViewer Full Client and Host for Linux and macOS versions prior to 15.82, specifically when processing .tvs session recording files. This flaw allows an attacker to execute arbitrary code with the current user's privileges by tricking them into opening a malicious session recording. Organizations using affected versions should prioritize patching to mitigate the risk of potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92368
Severity
HIGH
CVSS
7.8
EPSS
0.14%
Linux

Original NVD Description

TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user