CVE-2026-23566

MEDIUM

TeamViewer DEX Client <26.1 - Log Injection

Title source: llm
STIX 2.1

Description

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an attacker on the adjacent network to inject, tamper with, or forge log entries in \Nomad Branch.log via crafted data sent to the UDP network handler. This can impact log integrity and nonrepudiation.

Scores

CVSS v3 6.5
EPSS 0.0006
EPSS Percentile 19.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
teamviewer/digital_employee_experience < 26.1
Published Jan 29, 2026
Tracked Since Feb 18, 2026