
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23572 is an improper access control vulnerability (CWE-863: Incorrect Authorization) in TeamViewer Full and Host clients for Windows, macOS, and Linux. It allows an authenticated remote user to bypass the "Allow after confirmation" access control setting during a remote session, gaining unauthorized access before local confirmation is granted. Affected products include TeamViewer Remote, Tensor, and One (all versions prior to 15.74.5). The vulnerability was published on February 5, 2026, with a CVSS v3.1 base score of 7.2 (High) (TeamViewer Advisory, Red Hat CVE).
The root cause is incorrect authorization (CWE-863) in the TeamViewer client's handling of the "Allow after confirmation" access control configuration during active remote sessions. When this setting is enabled, it is intended to require explicit local user approval before granting certain remote access actions; however, an authenticated remote user can circumvent this confirmation step and gain access prematurely. Exploitation requires the attacker to already be authenticated to the remote session via ID/password, Session Link, or Easy Access — meaning unauthenticated exploitation is not possible. No public proof-of-concept exploit code has been identified at this time (TeamViewer Advisory, Heise News).
Successful exploitation allows an authenticated remote attacker to bypass local confirmation prompts and gain unauthorized access to the target system within an active TeamViewer session. This can result in high confidentiality, integrity, and availability impacts — the attacker could read sensitive data, modify system configurations, install malware, or disrupt services on the affected host. The scope is limited to systems running vulnerable TeamViewer Full or Host clients (Windows, macOS, Linux) where the "Allow after confirmation" policy is configured (TeamViewer Advisory, Techzine).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.043% (0.000430), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires prior authentication to the remote session, which significantly limits the attacker pool (TeamViewer Advisory, Red Hat CVE).
%AppData%\TeamViewer\TeamViewer15_Logfile.log (Windows) or equivalent on macOS/Linux.TeamViewer has released version 15.74.5 of the Full and Host clients for Windows, macOS, and Linux, which resolves this vulnerability. Organizations should update all affected TeamViewer Remote, Tensor, and One deployments to version 15.74.5 or later immediately. As an interim measure, administrators can restrict TeamViewer access using allowlists, enforce Easy Access with strong authentication, and monitor session logs for anomalous activity. Disabling or tightly controlling the "Allow after confirmation" feature in environments where it is not strictly required can also reduce exposure (TeamViewer Advisory).
Heise reported on the vulnerability, noting that it allowed remote access without prior local confirmation and highlighting the patch in version 15.74.5 (Heise News). Techzine covered the story emphasizing the bypass of permission checks (Techzine). Igor's Lab noted TeamViewer's closure of the "critical access gap" without a confirmation prompt (Igor's Lab). Community discussion on Reddit's r/Action1 referenced the TeamViewer 15.74.5 update in the context of patch management (Reddit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."