Junglewise Threat Intelligence

CVE-2026-2695: TeamViewer DEX Platform command injection in instruction input

CVE-2026-2695 · Severity: medium · CVSS 6.3 · Published 2026-05-13

Vendors: Teamviewer.

Executive brief

A command injection vulnerability exists in TeamViewer DEX Platform On-Premises, a tool used for digital employee experience monitoring and device management. An authenticated user with basic 'questioner' permissions can bypass security checks to run unauthorized commands on devices managed by the platform. This could allow an attacker to gain elevated control over connected corporate hardware, potentially leading to data theft or system disruption.

Technical details

A command injection vulnerability (CWE-20) exists in TeamViewer DEX Platform On-Premises (formerly 1E DEX) prior to version 9.2. The flaw is caused by a lack of server-side validation in the instruction input component. An authenticated attacker with at least 'questioner' privileges can submit specially crafted instructions to inject and execute arbitrary commands. Successful exploitation allows for the execution of elevated commands on all devices connected to and managed by the platform. The issue is resolved in version 9.2; SaaS customers are not affected.

Affected products

  • TeamViewer DEX Platform On-Premises < 9.2

Timeline

  • 2026-05-13: disclosed
  • 2026-05-13: advisory
  • 2026-05-13: patched: Fixed in version 9.2

References

Related threats