Input validation error in Digital Employee Experience (DEX) Client for Windows - CVE-2025-46266

 

Input validation error in Digital Employee Experience (DEX) Client for Windows - CVE-2025-46266

Published: December 11, 2025


Vulnerability identifier: #VU119846
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-46266
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied input within the Content Distribution Service (NomadBranch.exe). A remote attacker on the local network can force the service into transmitting data to an arbitrary internal IP address, leading to information disclosure. 


Affected software

Digital Employee Experience (DEX) Client for Windows

How to mitigate CVE-2025-46266

Install updates from vendor's website.

Digital Employee Experience (DEX) Client for Windows - update to 25.11.0.29

External References

Related Security Bulletins