On September 29, TeamViewer published bulletin TV-2026-1010 covering five vulnerabilities in its clients and related services. The flaws affect Full Client and Host on Windows, macOS and Linux. The highest-scored issue, CVE-2026-92370, affects permissions applied to remote sessions.
Five flaws with different effects
The bulletin covers path traversal, a buffer overflow, a race condition and an access-control issue. Depending on the flaw and platform, consequences range from local privilege escalation to code execution after opening a specially crafted recording.
This is not one scenario that applies to every installation. Preconditions, platforms and affected versions differ by CVE; TeamViewer’s advisory lists the relevant products and maintenance branches.
The session-control issue
CVE-2026-92370 has a CVSS score of 8.8. TeamViewer describes a remote attacker modifying some access-control parameters while establishing a session and bypassing restrictions configured by the user. The bulletin calls the attacker authenticated, while its CVSS vector lists PR:N (no prior privileges) and UI:R (user interaction required). This wording leaves the authentication prerequisite unclear; possible actions depend on the permissions exposed by the host.
TeamViewer says unauthorized actions may result and could lead to code execution on the target system. When assessing this scenario, do not infer operational prerequisites from the CVSS score alone; ask TeamViewer to clarify the difference between the prose and the vector.
Update clients and hosts
TeamViewer recommends installing the latest available version as soon as possible. Version 15.82 fixes several issues in current branches, but some older maintenance branches have different fixed versions. Check each operating system and product against the vendor’s affected-version table.
After updating, review the permissions available during a session, especially remote control and file access. Support teams can also confirm that temporary sessions close as expected and shared accounts remain limited to people who need them.
Exploitation status at the time of the bulletin
TeamViewer says it was not aware of public disclosure or exploitation in the wild when it published the bulletin. This is the vendor’s stated knowledge at that time, not proof that no system was targeted. Apply the fixes without attributing the flaws to an unverified campaign.
How Soclyde fits
Soclyde does not secure TeamViewer sessions or remove these vulnerabilities. For a team using remote access, an encrypted vault can help manage unique secrets and limit sharing to authorized people, alongside session controls and software updates. Our secure password generator guide explains how to create distinct secrets for these accounts.
Key points
Install the fixed versions for the platforms in use, then review remote-session permissions. TeamViewer’s bulletin leaves the authentication prerequisite for CVE-2026-92370 unclear; account for that when assessing risk. For team secrets, see our guide to secure password sharing or contact Soclyde.



