CVE-2026-23568
Out-of-Bounds Read in TeamViewer NomadBranch.exe Causes Data Leak
Publication date: 2026-01-29
Last updated on: 2026-02-11
Assigner: TeamViewer Germany GmbH
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| teamviewer | digital_employee_experience | to 26.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an out-of-bounds read in the TeamViewer DEX Client's Content Distribution Service (NomadBranch.exe) prior to version 26.1 for Windows. It allows an attacker on the adjacent network to send a specially crafted packet that causes the program to read memory outside its intended boundaries, potentially leading to information disclosure or denial-of-service.
How can this vulnerability impact me? :
The vulnerability can lead to information disclosure by leaking memory contents, which could help an attacker bypass Address Space Layout Randomization (ASLR) and facilitate further exploitation. It can also cause denial-of-service conditions, disrupting the normal operation of the affected service.