Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-23572
TeamViewer Remote vulnerability analysis and mitigation

Overview

CVE-2026-23572 is an improper access control vulnerability (CWE-863: Incorrect Authorization) in TeamViewer Full and Host clients for Windows, macOS, and Linux. It allows an authenticated remote user to bypass the "Allow after confirmation" access control setting during a remote session, gaining unauthorized access before local confirmation is granted. Affected products include TeamViewer Remote, Tensor, and One (all versions prior to 15.74.5). The vulnerability was published on February 5, 2026, with a CVSS v3.1 base score of 7.2 (High) (TeamViewer Advisory, Red Hat CVE).

Technical details

The root cause is incorrect authorization (CWE-863) in the TeamViewer client's handling of the "Allow after confirmation" access control configuration during active remote sessions. When this setting is enabled, it is intended to require explicit local user approval before granting certain remote access actions; however, an authenticated remote user can circumvent this confirmation step and gain access prematurely. Exploitation requires the attacker to already be authenticated to the remote session via ID/password, Session Link, or Easy Access — meaning unauthenticated exploitation is not possible. No public proof-of-concept exploit code has been identified at this time (TeamViewer Advisory, Heise News).

Impact

Successful exploitation allows an authenticated remote attacker to bypass local confirmation prompts and gain unauthorized access to the target system within an active TeamViewer session. This can result in high confidentiality, integrity, and availability impacts — the attacker could read sensitive data, modify system configurations, install malware, or disrupt services on the affected host. The scope is limited to systems running vulnerable TeamViewer Full or Host clients (Windows, macOS, Linux) where the "Allow after confirmation" policy is configured (TeamViewer Advisory, Techzine).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.043% (0.000430), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires prior authentication to the remote session, which significantly limits the attacker pool (TeamViewer Advisory, Red Hat CVE).

Exploitation steps

  1. Authenticate to target session: Establish an authenticated TeamViewer remote session to the target host using valid credentials (ID/password), a Session Link, or Easy Access — this is a mandatory prerequisite.
  2. Identify confirmation policy: Confirm that the target system has the "Allow after confirmation" access control setting enabled, which is intended to require local user approval for certain actions.
  3. Bypass confirmation prompt: Exploit the improper authorization logic in the vulnerable client (prior to version 15.74.5) to perform restricted actions (e.g., file transfer, remote control escalation) without waiting for or receiving local user confirmation.
  4. Achieve unauthorized access: Gain full or elevated access to the remote system's resources — reading files, executing commands, or modifying configurations — before the local user is aware or can respond (TeamViewer Advisory, Heise News).

Indicators of compromise

  • Logs: TeamViewer session logs showing remote access actions (file transfers, remote control events) occurring before any local confirmation dialog was acknowledged; review %AppData%\TeamViewer\TeamViewer15_Logfile.log (Windows) or equivalent on macOS/Linux.
  • Network: Unexpected or prolonged TeamViewer session connections from unfamiliar IDs or IP addresses, particularly outside normal business hours.
  • Process: Unusual child processes or file system changes initiated during an active TeamViewer session without corresponding local user activity.
  • File System: Unexpected files created or modified in user directories during a TeamViewer session timeframe, potentially indicating unauthorized file transfer activity (TeamViewer Advisory).

Mitigation and workarounds

TeamViewer has released version 15.74.5 of the Full and Host clients for Windows, macOS, and Linux, which resolves this vulnerability. Organizations should update all affected TeamViewer Remote, Tensor, and One deployments to version 15.74.5 or later immediately. As an interim measure, administrators can restrict TeamViewer access using allowlists, enforce Easy Access with strong authentication, and monitor session logs for anomalous activity. Disabling or tightly controlling the "Allow after confirmation" feature in environments where it is not strictly required can also reduce exposure (TeamViewer Advisory).

Community reactions

Heise reported on the vulnerability, noting that it allowed remote access without prior local confirmation and highlighting the patch in version 15.74.5 (Heise News). Techzine covered the story emphasizing the bypass of permission checks (Techzine). Igor's Lab noted TeamViewer's closure of the "critical access gap" without a confirmation prompt (Igor's Lab). Community discussion on Reddit's r/Action1 referenced the TeamViewer 15.74.5 update in the context of patch management (Reddit).

Additional resources


SourceThis report was generated using AI

Related TeamViewer Remote vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12703HIGH8
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesJul 29, 2026
CVE-2025-0065HIGH7.8
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesJan 28, 2025
CVE-2026-23572HIGH7.2
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesFeb 05, 2026
CVE-2025-36537HIGH7
  • TeamViewer Remote logoTeamViewer Remote
  • cpe:2.3:a:teamviewer:remote
NoYesJun 24, 2025
CVE-2024-6053MEDIUM4.3
  • TeamViewer Remote logoTeamViewer Remote
  • teamviewer
NoYesAug 28, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management