TEAMVIEWER has disclosed five high-severity vulnerabilities affecting its Full Client and Host across Windows, Linux, and macOS, with fixes included in version 15.82. The most severe flaw, CVE-2026-92370, carries a CVSS score of 8.8 and is described as a permission-bypass in session initialisation that can let a remote attacker alter access controls and potentially trigger remote code execution, albeit requiring some victim interaction.
Four additional local privilege escalation issues are present: CVE-2026-19743 (CVSS 7.8) in the local IPC service; CVE-2026-92369 (CVSS 7.3) via an installer rollback race on Windows; CVE-2026-92371 (CVSS 7.0) affecting Cloud Session Recording on Linux; and CVE-2026-92368 (CVSS 7.8) a heap overflow in the Linux/macOS .tvs session recording parser that can be exploited by convincing a user to open a crafted recording. None of these five flaws have been confirmed as exploited in the wild according to the report.
Affected products include TeamViewer 15.x releases prior to 15.82 (with legacy Windows builds 15.64.8, 14.7.48855, and 13.2 also listed for respective platforms). The advisory urges organisations to apply the patch promptly by updating to 15.82; legacy users should move to 15.64.8, 14.7.48855, or the fixed 13.2 build for their platform.
In the interim, users should avoid opening .tvs files from unknown sources and limit local logins to devices running TeamViewer, as most of these vulnerabilities require local access.