CVE-2026-2695: Lack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises)
A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution of elevated commands on devices connected to the platform.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2695?
CVE-2026-2695 is classified as a command injection vulnerability with a high severity level due to its potential impact on system integrity.
How do I fix CVE-2026-2695?
To fix CVE-2026-2695, upgrade your TeamViewer DEX Platform On-Premises to version 9.2 or later.
Who is affected by CVE-2026-2695?
CVE-2026-2695 affects all versions of TeamViewer DEX Platform On-Premises prior to version 9.2.
What causes CVE-2026-2695?
CVE-2026-2695 is caused by a lack of server-side validation in instruction input, allowing for command injection by authenticated users.
Can CVE-2026-2695 be exploited remotely?
Yes, CVE-2026-2695 can potentially be exploited remotely by authenticated users who have access to the affected system.