CVE-2026-8381: Broken Access Control in TeamViewer DEX Platform (On Premises)
A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior version 9.2. Certain backend API endpoints do not correctly enforce authorization checks, allowing an authenticated user with low privileges to perform actions and access resources intended only for higher‑privileged roles. An attacker with low‑privileged credentials may exploit this to gain unauthorized access to administrative or sensitive functionality.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
TeamViewer DEX Platform (On Premises)to a version that resolves this vulnerability.Fixed in 9.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8381?
CVE-2026-8381 has a medium severity rating of 5.4.
How do I fix CVE-2026-8381?
To fix CVE-2026-8381, you should update to version 9.2 or the latest version of the TeamViewer DEX Platform (On-Premises).
What type of vulnerability is CVE-2026-8381?
CVE-2026-8381 is a broken access control vulnerability.
Which software is affected by CVE-2026-8381?
CVE-2026-8381 affects the TeamViewer DEX Platform (On-Premises) prior to version 9.2.
What are the risks associated with CVE-2026-8381?
The risks associated with CVE-2026-8381 include allowing low-privileged authenticated users to access resources meant for higher privilege users.