Input validation error in Digital Employee Experience (DEX) Client for Windows - CVE-2026-23566
Published: January 30, 2026
Vulnerability identifier: #VU122140
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23566
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the Log injection issue in Content Distribution Service UDP Handler. A remote attacker on the local network can send specially crafted data to the UDP network handler and impact log integrity and nonrepudiation.
Affected software
Digital Employee Experience (DEX) Client for Windows
How to mitigate CVE-2026-23566
Install updates from vendor's website.
Digital Employee Experience (DEX) Client for Windows - update to 26.1