Input validation error in Digital Employee Experience (DEX) Client for Windows - CVE-2026-23570
Published: January 30, 2026
Vulnerability identifier: #VU122146
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23570
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to missing validation of a user-controlled value in Content Distribution Service. A remote attacker on the local network can use specially crafted UDP Sync command to tamper with log timestamps.
Affected software
Digital Employee Experience (DEX) Client for Windows
How to mitigate CVE-2026-23570
Install updates from vendor's website.
Digital Employee Experience (DEX) Client for Windows - update to 26.1