Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-12703
TeamViewer Remote vulnerability analysis and mitigation

Overview

CVE-2026-12703 is a business logic authentication bypass vulnerability in TeamViewer Full Client and Host for macOS that allows an authenticated attacker to circumvent a configured two-factor authentication (2FA) requirement for the Connections approval flow via Unattended Access, enabling unauthorized remote connections to affected macOS hosts. It affects TeamViewer Remote, Tensor, and ONE products from version 15.00 up to (but not including) version 15.80. The vulnerability was published on July 29, 2026, and carries a CVSS v3.1 base score of 8.0 (High) (GitHub Advisory, TeamViewer Bulletin).

Technical details

The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), stemming from a business logic error in the Connections approval flow. Specifically, the Unattended Access feature provides an alternate path that does not enforce the configured 2FA check, allowing an attacker who already holds high-privilege credentials to bypass the second authentication factor entirely. Exploitation requires network access, high privileges, and high attack complexity, but no user interaction, and the scope change indicates impact can extend beyond the directly vulnerable component (GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker with high privileges to establish a remote connection to an affected macOS host without completing the required 2FA challenge, effectively nullifying a key security control. The impact spans confidentiality, integrity, and availability — all rated High — meaning an attacker could access sensitive data, modify system state, or disrupt services on the compromised host. This could facilitate insider threats or account-takeover scenarios where an attacker with stolen high-privilege credentials bypasses the additional authentication layer intended to prevent unauthorized remote access (GitHub Advisory, TeamViewer Bulletin).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.234% (14th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high privileges and high attack complexity, limiting the attacker pool to authenticated insiders or those who have already compromised high-privilege credentials.

Exploitation steps

  1. Obtain High-Privilege Credentials: Acquire valid TeamViewer credentials with high-level access to the target macOS host, either through phishing, credential theft, or insider access.
  2. Identify Target: Confirm the target macOS host is running TeamViewer Full Client or Host version 15.00–15.79 with 2FA configured for the Connections approval flow.
  3. Initiate Unattended Access Connection: Instead of using the standard connection flow (which triggers the 2FA prompt), initiate a connection via the Unattended Access channel, which contains the business logic error that skips the 2FA enforcement.
  4. Bypass 2FA: The alternate Unattended Access path does not invoke the 2FA check, allowing the connection to proceed without the second factor being presented or validated.
  5. Establish Remote Session: Gain full remote access to the macOS host, enabling data exfiltration, system modification, or further lateral movement within the network (GitHub Advisory, TeamViewer Bulletin).

Indicators of compromise

  • Logs: TeamViewer connection logs showing Unattended Access sessions established without a corresponding 2FA approval event; review TeamViewer<version>_Logfile.log on macOS for connection entries lacking MFA confirmation records.
  • Network: Unexpected outbound or inbound TeamViewer relay traffic (typically over TCP/UDP port 5938 or HTTPS port 443 to TeamViewer infrastructure) from macOS hosts during off-hours or from unusual source accounts.
  • Process: TeamViewer Host or Full Client processes initiating remote sessions without user-visible prompts or approval dialogs on the macOS host.
  • Access Patterns: High-privilege TeamViewer accounts establishing connections to macOS hosts at unusual times or from unfamiliar geographic locations, particularly via Unattended Access rather than attended session flows.

Mitigation and workarounds

TeamViewer has released version 15.80 of TeamViewer Remote, Tensor, and ONE for macOS, which resolves this vulnerability. Organizations should update all affected macOS installations of TeamViewer Full Client and Host to version 15.80 or later as the primary remediation (TeamViewer Bulletin). As interim measures while patching is pending, consider implementing network-level restrictions on TeamViewer connections (e.g., allowlisting approved source IPs), disabling Unattended Access where not operationally required, and reviewing TeamViewer access logs for suspicious remote connection activity.

Community reactions

Heise Online covered the vulnerability shortly after disclosure, noting the 2FA bypass risk on macOS (Heise). General community reaction has been moderate, with aggregator sites such as VulDB and Vulners indexing the CVE promptly. No significant independent researcher commentary or widespread social media discussion has been identified beyond standard vulnerability tracking coverage.

Additional resources


SourceThis report was generated using AI

Related TeamViewer Remote vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12703HIGH8
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesJul 29, 2026
CVE-2025-0065HIGH7.8
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesJan 28, 2025
CVE-2026-23572HIGH7.2
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesFeb 05, 2026
CVE-2025-36537HIGH7
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesJun 24, 2025
CVE-2024-6053MEDIUM4.3
  • TeamViewer Remote logoTeamViewer Remote
  • teamviewer
NoYesAug 28, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management