Skip to content

Executive Summary

TeamViewer released security updates addressing five high-severity vulnerabilities in the Full Client and Host across Windows, Linux, and macOS platforms on Thursday, October 1, 2026. The most severe vulnerability, CVE-2026-92370 (CVSS score 8.8), stems from improper permission controls during remote sessions, potentially allowing an attacker to bypass settings and execute commands. Other vulnerabilities include CVE-2026-19743, which could lead to privilege escalation via file writing with SYSTEM or root permissions; CVE-2026-92368, a heap-based buffer overflow on Linux and macOS linked to session recording files that could enable command execution; CVE-2026-92369, a race condition in the installer rollback process on Windows that might cause privilege escalation; and CVE-2026-92371, affecting the Cloud Session Recording feature on Linux, which permits unintended file creation or modification with elevated privileges.
These vulnerabilities have been remediated in TeamViewer version 15.82 and its supported Maintenance and Legacy releases. Users are advised to update their software immediately to ensure they benefit from these fixes. Versions prior to 15.82 on Windows, Linux, and macOS may remain susceptible to some of the identified issues.

Facts Only

* TeamViewer released security updates for five high-severity vulnerabilities on Thursday, October 1, 2026.
* The most severe vulnerability is CVE-2026-92370, rated at a CVSS score of 8.8, resulting from improper permission controls during remote sessions.
* CVE-2026-92370 could allow an attacker to bypass permission settings and potentially execute commands on the target system.
* Other vulnerabilities include CVE-2026-19743, allowing limited privilege users to write files with SYSTEM or root permissions and escalate privileges.
* CVE-2026-92368 is a heap-based buffer overflow on Linux and macOS that could lead to command execution if a specially crafted .tvs session recording file is opened.
* CVE-2026-92369 is a race condition in the installer rollback process on Windows that could result in privilege escalation.
* CVE-2026-92371 affects the Cloud Session Recording feature on Linux and can allow files to be created or modified with elevated privileges.
* All vulnerabilities are fixed in TeamViewer version 15.82 and supported Maintenance/Legacy releases.
* Users should update their TeamViewer Full Client and Host to the latest available release immediately.

Full Take

The sequence of disclosures reveals a known operational tension between security posture and feature complexity within remote access software. The existence of multiple, distinct vulnerabilities stemming from permission handling (CVE-2026-92370, CVE-2026-19743) and memory/process management (CVE-2026-92368, CVE-2026-92371) suggests that the complexity introduced by advanced features—such as session recording or installer rollbacks—introduces significant, often exploitable attack surfaces where default permissions are not strictly enforced. The narrative frames a rapid patch rollout in version 15.82, which implies an acknowledgment of systemic fragility requiring immediate correction rather than gradual mitigation.
The implication for user agency centers on the distribution of risk: while TeamViewer provided transparency regarding specific flaws and solutions, the reality for end-users is dependent on timely action. The fact that older versions might be affected creates a dynamic where security compliance shifts from a fixed state to an ongoing obligation for vigilance based on version management. This pattern suggests that when sophisticated features are layered onto core access mechanisms, the risk profile scales non-linearly with feature density.
The missing element in this reporting is the structural context: why do these specific permission flaws manifest? Do they reflect an architectural decision where remote session management or file handling operates outside strict host-level separation? The pattern points toward a dynamic where security fixes are reactive responses to introduced complexity rather than proactive design, forcing users into a perpetual state of retroactive risk assessment.
Bridge Questions:
How does the architecture of multi-platform remote session controls correlate with the severity and specific vectors of permission-based vulnerabilities discovered across different operating systems?
What responsibility exists for developers in designing systems where complex features inherently introduce race conditions or privilege escalation pathways, rather than simply patching discrete bugs?
If immediate updates are presented as the sole solution, how can users develop a resilience framework that manages risk during inevitable gaps between discovery and deployment of fixes?

From the original · Thailand ThaiCERT Advisories

540/69 Thursday, October 1, 2026 TeamViewer has released security updates to address five High-severity vulnerabilities in TeamViewer Full Client and Host on Windows, Linux, and macOS. The most severe vulnerability is CVE-2026-92370, with a CVSS score of 8.8, caused by improper permission controls during remote sessions.
Read the full story at thaicert.or.th

Sentinel — Human

Confidence

This text exhibits characteristics of official corporate security communication, presenting specific facts and required actions without the stylistic markers typically associated with synthetic content.

Signals Detected
low severity: Moderate sentence length variance; direct and factual tone.
low severity: High coherence; focused entirely on technical disclosure and remediation steps.
low severity: Standard press release structure; direct attribution to the vendor (TeamViewer).
low severity: Claims rely on specific, verifiable CVE numbers and version releases.
Human Indicators
The text reads like a formal security advisory or press release, using precise technical terminology and direct instruction. It lacks the characteristic hedging or overly broad synthesis common in AI-generated general commentary.
TeamViewer Full Client and Host Vulnerabilities Could Allow Command Execution and Privilege Escalation | Huntaegis