A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical datetime prefixes and compromising log integrity and forensic correlation.
References
| Link | Resource |
|---|---|
| https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1001/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
11 Feb 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Teamviewer digital Employee Experience
Teamviewer Microsoft Microsoft windows |
|
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:teamviewer:digital_employee_experience:*:*:*:*:*:*:*:* |
|
| References | () https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1001/ - Vendor Advisory |
29 Jan 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-29 09:16
Updated : 2026-02-11 20:17
NVD link : CVE-2026-23570
Mitre link : CVE-2026-23570
CVE.ORG link : CVE-2026-23570
JSON object : View
Products Affected
teamviewer
- digital_employee_experience
microsoft
- windows
CWE
CWE-20
Improper Input Validation
