{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-2695",
        "assignerOrgId": "13430f76-86eb-43b2-a71c-82c956ef31b6",
        "state": "PUBLISHED",
        "assignerShortName": "TV",
        "dateReserved": "2026-02-18T14:30:36.890Z",
        "datePublished": "2026-05-13T16:09:08.776Z",
        "dateUpdated": "2026-05-13T17:45:24.249Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "13430f76-86eb-43b2-a71c-82c956ef31b6",
                "shortName": "TV",
                "dateUpdated": "2026-05-13T16:09:08.776Z"
            },
            "title": "Lack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises)",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-20",
                            "description": "CWE-20 Improper input validation",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "TeamViewer",
                    "product": "DEX (On-Premises)",
                    "modules": [
                        "Platform"
                    ],
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "9.2",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "A command\ninjection vulnerability was discovered in TeamViewer DEX Platform On-Premises\n(former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows\nauthenticated users with at least questioner privileges to inject commands in specific\ninstructions. Exploitation could lead to execution of elevated commands on\ndevices connected to the platform.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p>A command\ninjection vulnerability was discovered&nbsp;in TeamViewer DEX Platform On-Premises\n(former 1E DEX Platform On-Premises) prior to version 9.2.&nbsp;Improper input validation allows\nauthenticated users with at least questioner privileges to inject commands in specific\ninstructions. Exploitation could lead to execution of elevated commands on\ndevices connected to the platform.&nbsp;</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.teamviewer.com/de/resources/trust-center/security-bulletins/tv-2026-1004/"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "LOW",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "LOW",
                        "integrityImpact": "LOW",
                        "availabilityImpact": "LOW",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 6.3,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Update to the latest version (v9.2 or the latest available version).",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Update to the latest version (v9.2 or the latest available version)."
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Lockheed Martin Red Team",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.2"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-05-13T17:19:55.259243Z",
                                "id": "CVE-2026-2695",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-05-13T17:45:24.249Z"
                }
            }
        ]
    }
}