Junglewise Threat Intelligence

CVE-2026-8381: TeamViewer DEX Platform broken access control in backend API

CVE-2026-8381 · Severity: medium · CVSS 5.4 · Published 2026-05-22

Vendors: Teamviewer.

Executive brief

A security flaw in the TeamViewer DEX Platform (On-Premises) allows users with standard access to perform administrative tasks or view sensitive information they should not be able to see. This occurs because certain backend systems do not properly verify a user's permission level before processing requests. An attacker with basic login credentials could exploit this to gain unauthorized control over administrative functions or access restricted data.

Technical details

A broken access control vulnerability (CWE-862) exists in the TeamViewer DEX Platform (On-Premises) prior to version 9.2. The root cause is a failure in certain backend API endpoints to correctly enforce server-side authorization checks. An attacker with valid, low-privileged credentials can send crafted requests to these endpoints to perform actions or access resources intended only for higher-privileged roles. The vulnerability is reachable over the network and does not require user interaction. TeamViewer has addressed this issue in version 9.2.

Affected products

  • TeamViewer DEX Platform (On-Premises) < 9.2

Timeline

  • 2026-05-22: advisory: TeamViewer security bulletin TV-2026-1005 published
  • 2026-05-22: disclosed: CVE-2026-8381 published to NVD
  • 2026-05-22: patched: Fix released in version 9.2

References

Related threats