CVE 6.8 MEDIUM

Command Injection in 1E-Nomad-RunPkgStatusRequest Instruction in TeamViewer DEX_CVE-2026-23571

6.8 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Description

A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary commands on connected hosts via malicious commands injected into the instruction’s input field. Users of 1E Client version 24.5 or higher are not affected.

Basic Information

ID CVE-2026-23571
Source TV
Published Jan 29, 2026 at 08:41

Affected Product

Vendor TeamViewer
Product DEX
Affected Versions TeamViewer DEX 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.