🔐 CVE Alert

CVE-2026-92368

HIGH 7.8

Heap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to Remote Code Execution

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user

CWE CWE-122
Vendor teamviewer
Product full client
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for teamviewer full client

Be the first to know when new high vulnerabilities affecting teamviewer full client are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

TeamViewer / Full Client
15.70 < 15.82
TeamViewer / Host
15.70 < 15.82

References

NVD ↗ CVE.org ↗ EPSS Data ↗
teamviewer.com: https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/

Credits

We thank HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL) for the discovery and responsible disclosure.