Junglewise Threat Intelligence

CVE-2026-12703: TeamViewer macOS 2FA bypass in Unattended Access connection flow

CVE-2026-12703 · Severity: high · CVSS 8 · Published 2026-07-29

Vendors: Teamviewer.

Executive brief

TeamViewer for macOS contains a security flaw that allows an authorized user with management permissions to bypass two-factor authentication (2FA) when connecting to a remote computer. This occurs specifically when 'Unattended Access' is configured, potentially allowing an attacker to gain full remote control of a macOS system without the required secondary approval. Organizations using TeamViewer to manage macOS fleets should update to version 15.80 or later to ensure connection security policies are enforced.

Technical details

A business logic error (CWE-288) exists in the TeamViewer macOS client and host components regarding the 'Connections' approval flow. An authenticated attacker with high privileges (specifically device management permissions for pre-authenticated macOS devices) can exploit this flaw to bypass configured two-factor authentication requirements when using the Unattended Access feature. By utilizing an alternate path in the connection logic, the attacker can establish a full remote session without the secondary approval trigger. The vulnerability is fixed in version 15.80; it does not affect TeamViewer Conditional Access policies.

Affected products

  • TeamViewer Remote Full Client < 15.80
  • TeamViewer Remote Host < 15.80
  • TeamViewer Tensor Full Client < 15.80
  • TeamViewer ONE Full Client < 15.80

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: patched: Fixed in version 15.80
  • 2026-07-29: advisory

References