Input validation error in Digital Employee Experience (DEX) Client for Windows - CVE-2026-23570

 

Input validation error in Digital Employee Experience (DEX) Client for Windows - CVE-2026-23570

Published: January 30, 2026


Vulnerability identifier: #VU122146
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-23570
CWE-ID: CWE-20
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to missing validation of a user-controlled value in Content Distribution Service. A remote attacker on the local network can use specially crafted UDP Sync command to tamper with log timestamps.


Affected software

Digital Employee Experience (DEX) Client for Windows

How to mitigate CVE-2026-23570

Install updates from vendor's website.

Digital Employee Experience (DEX) Client for Windows - update to 26.1

External References

Related Security Bulletins