OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-92370

HIGH · CVSS 8.8 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

An improper access control vulnerability in TeamViewer allows authenticated remote attackers on Windows and Linux to bypass user-configured permission settings during session establishment. This can enable unauthorized actions, potentially leading to remote code execution on the affected systems. Organizations using TeamViewer should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92370
Severity
HIGH
CVSS
8.8
EPSS
0.38%
Windows Linux

Original NVD Description

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration. This may result in unauthorized actions and potentially lead to remote code execution on the target system.