A command
injection vulnerability was discovered in TeamViewer DEX Platform On-Premises
(former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows
authenticated users with at least questioner privileges to inject commands in specific
instructions. Exploitation could lead to execution of elevated commands on
devices connected to the platform.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

Update to the latest version (v9.2 or the latest available version).


Workaround

No workaround given by the vendor.

History

Wed, 13 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 13 May 2026 17:15:00 +0000

Type Values Removed Values Added
Description A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution of elevated commands on devices connected to the platform.
Title Lack of Server-side validation in Instruction Input in TeamViewer DEX Platform (On-Premises)
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TV

Published:

Updated: 2026-05-13T17:45:24.249Z

Reserved: 2026-02-18T14:30:36.890Z

Link: CVE-2026-2695

cve-icon Vulnrichment

Updated: 2026-05-13T17:45:18.243Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-13T17:16:19.453

Modified: 2026-05-13T18:10:51.227

Link: CVE-2026-2695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses