CVE-2026-12703
Deferred Deferred - Pending Action

TeamViewer macOS Client Host 2FA Bypass via Unattended Access

Vulnerability report for CVE-2026-12703, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-29

Last updated on: 2026-07-29

Assigner: TeamViewer Germany GmbH

Description

TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-29
Last Modified
2026-07-29
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
teamviewer full_client to 15.80 (exc)
teamviewer host to 15.80 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-288 The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

TeamViewer Full Client and Host for macOS before version 15.80 has a business logic error that allows an authenticated attacker to bypass two-factor authentication (2FA) in the Connections approval flow. This is done via Unattended Access, enabling the attacker to establish a remote connection to the affected macOS host without proper authentication.

Impact Analysis

If you use TeamViewer Full Client or Host on macOS before version 15.80, an attacker could bypass 2FA and gain unauthorized remote access to your system. This could lead to data theft, system compromise, or further attacks within your network.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Organizations may face legal penalties, reputational damage, and loss of trust due to non-compliance.

Mitigation Strategies

Update TeamViewer Full Client and Host for macOS to version 15.80 or later to address the business logic error affecting the 2FA bypass in Connections approval flow via Unattended Access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12703. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart