CVE-2026-2695 MEDIUM

CVE-2026-2695: Lack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises)

Vendor Teamviewer
Product DEX (On-Premises)
Weakness CWE-20 · Input validation
Published May 13, 2026
Last update May 13, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution of elevated commands on devices connected to the platform.

Key dates

02Disclosure timeline

May 13, 2026 CVE published
May 13, 2026 Record updated