CVE-2026-23569

MEDIUM

TeamViewer DEX Client <26.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

An out-of-bounds read vulnerability in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows a remote attacker to leak stack memory and cause a denial of service via a crafted request. The leaked stack memory could be used to bypass ASLR remotely and facilitate exploitation of other vulnerabilities on the affected system.

Scores

CVSS v3 6.5
EPSS 0.0005
EPSS Percentile 16.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (1)
teamviewer/digital_employee_experience < 26.1
Published Jan 29, 2026
Tracked Since Feb 18, 2026