CVE-2026-12703
HIGHBypass of 2FA for Connections via Unattended Access in TeamViewer for macOS
Title source: cnaDescription
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1007/
Scores
CVSS v3
8.0
EPSS
0.0023
EPSS Percentile
14.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-288
Status
published
Products (3)
TeamViewer/ONE
15.00 - 15.80
TeamViewer/Remote
15.00 - 15.80
TeamViewer/Tensor
15.00 - 15.80
Published
Jul 29, 2026
Tracked Since
Jul 29, 2026