CVE-2026-23570: Log timestamp tampering vulnerability in Content Distribution Service
A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sync command. This could result in forged or nonsensical datetime prefixes and compromising log integrity and forensic correlation.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23570?
CVE-2026-23570 is rated as a high severity vulnerability due to the potential for log timestamp tampering by adjacent network attackers.
How do I fix CVE-2026-23570?
To fix CVE-2026-23570, upgrade to TeamViewer 1E Client version 26.1 or later.
What type of attack does CVE-2026-23570 enable?
CVE-2026-23570 allows an adjacent network attacker to tamper with log timestamps.
Which versions of TeamViewer are affected by CVE-2026-23570?
CVE-2026-23570 affects all versions of TeamViewer 1E Client prior to version 26.1.
What component of TeamViewer is affected by CVE-2026-23570?
CVE-2026-23570 affects the Content Distribution Service component in the TeamViewer DEX Client.