CVE-2026-23570

A

missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical datetime prefixes and compromising log integrity and forensic correlation.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:teamviewer:digital_employee_experience:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

11 Feb 2026, 20:17

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:teamviewer:digital_employee_experience:*:*:*:*:*:*:*:*
References () https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1001/ - () https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1001/ - Vendor Advisory
First Time Teamviewer
Microsoft
Teamviewer digital Employee Experience
Microsoft windows

29 Jan 2026, 09:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-29 09:16

Updated : 2026-02-11 20:17


NVD link : CVE-2026-23570

Mitre link : CVE-2026-23570

CVE.ORG link : CVE-2026-23570


JSON object : View

CWE
CWE-20

Improper Input Validation