Input validation error in Digital Employee Experience (DEX) Client for Windows - CVE-2026-23566

 

Input validation error in Digital Employee Experience (DEX) Client for Windows - CVE-2026-23566

Published: January 30, 2026


Vulnerability identifier: #VU122140
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23566
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the Log injection issue in Content Distribution Service UDP Handler. A remote attacker on the local network can send specially crafted data to the UDP network handler and impact log integrity and nonrepudiation.


Affected software

Digital Employee Experience (DEX) Client for Windows

How to mitigate CVE-2026-23566

Install updates from vendor's website.

Digital Employee Experience (DEX) Client for Windows - update to 26.1

External References

Related Security Bulletins