Command Injection in TeamViewer DEX Platform On-Premises <9.2
CVE-2026-2695 Published on May 13, 2026
Lack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises)
A command
injection vulnerability was discovered in TeamViewer DEX Platform On-Premises
(former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows
authenticated users with at least questioner privileges to inject commands in specific
instructions. Exploitation could lead to execution of elevated commands on
devices connected to the platform.
Vulnerability Analysis
CVE-2026-2695 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be low. considered to have a small impact on confidentiality and integrity and availability.
Weakness Type
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Affected Versions
TeamViewer DEX (On-Premises):- Before 9.2 is affected.