CVE-2025-46266

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
11/12/2025
Last modified:
14/01/2026

Description

A vulnerability in TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to coerce the service into transmitting data to an arbitrary internal IP address, potentially leaking sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:teamviewer:digital_employee_experience:*:*:*:*:*:*:*:* 25.11 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*