
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-12703 is a business logic authentication bypass vulnerability in TeamViewer Full Client and Host for macOS that allows an authenticated attacker to circumvent a configured two-factor authentication (2FA) requirement for the Connections approval flow via Unattended Access, enabling unauthorized remote connections to affected macOS hosts. It affects TeamViewer Remote, Tensor, and ONE products from version 15.00 up to (but not including) version 15.80. The vulnerability was published on July 29, 2026, and carries a CVSS v3.1 base score of 8.0 (High) (GitHub Advisory, TeamViewer Bulletin).
The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), stemming from a business logic error in the Connections approval flow. Specifically, the Unattended Access feature provides an alternate path that does not enforce the configured 2FA check, allowing an attacker who already holds high-privilege credentials to bypass the second authentication factor entirely. Exploitation requires network access, high privileges, and high attack complexity, but no user interaction, and the scope change indicates impact can extend beyond the directly vulnerable component (GitHub Advisory).
Successful exploitation allows an authenticated attacker with high privileges to establish a remote connection to an affected macOS host without completing the required 2FA challenge, effectively nullifying a key security control. The impact spans confidentiality, integrity, and availability — all rated High — meaning an attacker could access sensitive data, modify system state, or disrupt services on the compromised host. This could facilitate insider threats or account-takeover scenarios where an attacker with stolen high-privilege credentials bypasses the additional authentication layer intended to prevent unauthorized remote access (GitHub Advisory, TeamViewer Bulletin).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.234% (14th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high privileges and high attack complexity, limiting the attacker pool to authenticated insiders or those who have already compromised high-privilege credentials.
TeamViewer<version>_Logfile.log on macOS for connection entries lacking MFA confirmation records.TeamViewer has released version 15.80 of TeamViewer Remote, Tensor, and ONE for macOS, which resolves this vulnerability. Organizations should update all affected macOS installations of TeamViewer Full Client and Host to version 15.80 or later as the primary remediation (TeamViewer Bulletin). As interim measures while patching is pending, consider implementing network-level restrictions on TeamViewer connections (e.g., allowlisting approved source IPs), disabling Unattended Access where not operationally required, and reviewing TeamViewer access logs for suspicious remote connection activity.
Heise Online covered the vulnerability shortly after disclosure, noting the 2FA bypass risk on macOS (Heise). General community reaction has been moderate, with aggregator sites such as VulDB and Vulners indexing the CVE promptly. No significant independent researcher commentary or widespread social media discussion has been identified beyond standard vulnerability tracking coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."