TV-2026-1007

Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS

速報 ID
TV-2026-1007
Issue Date
2026/07/29
最終更新日
2026/07/29
優先度
Important(重要)
CVSS
8.0 (High)
割り当て CVE
CVE-2026-12703
影響のある製品
TeamViewer Remote
TeamViewer Tensor
TeamViewer ONE

1. Summary

A vulnerability has been discovered in TeamViewer Full Client and Host for macOS that may allow an authenticated attacker to bypass the configured 2FA for Connections approval flow on macOS hosts where Unattended Access is configured.

2. Vulnerability details

CVE-ID

Description

TeamViewer Remote Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host.

 

Successful exploitation requires the attacker to be authenticated and to possess device management permissions for pre-authenticated macOS devices.

 

For customers using Conditional Access, please note that this issue does not represent a bypass of TeamViewer Conditional Access policies themselves.

 

The vulnerability has been fixed with version 15.80 and additional versions listed below. We recommend updating to the latest available version.

 

At the time of publication, we are not aware of any prior public disclosure of this issue or any indication of exploitation in the wild.

CVSS3.1 Score

Base Score 8.0 (High)

CVSS3.1 Vector String

Problem type

3. Affected software and versions

Product
Versions
Info

TeamViewer Remote Full Client (macOS)

< 15.80

TeamViewer Remote Host (macOS)

< 15.80

4. Solutions and mitigations

Update to the latest version (15.80 or the latest version available)

5. Acknowledgements

We thank dameb for the discovery and responsible disclosure via TeamViewer’s Bug Bounty program.