CVE-2026-23572 describes an improper access control vulnerability in TeamViewer Full and Host clients (Windows, macOS, Linux) prior to version 15.74.5. An authenticated user can bypass "Allow after confirmation" settings in a remote session, leading to unauthorized access before local confirmation. This vulnerability carries a CVSS score of 7.2 (High), indicating a network attack vector with low complexity, requiring high privileges, and potentially resulting in high impact to confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor are there publicly available exploit tools like Metasploit or Nuclei modules. The vulnerability has also received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| TeamViewer | One | >= 0, < 15.74.5CNA affecteddefault unaffected | |
| TeamViewer | Remote | >= 0, < 15.74.5CNA affecteddefault unaffected | |
| TeamViewer | Tensor | >= 0, < 15.74.5CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.