[NotCVE-2026-0015] Input Leap through 3.0.3 input-leapd Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
Input Leap through 3.0.3 lets a local Windows user run commands as SYSTEM via unauthenticated IPC.
NotCVE-2026-0015 describes missing authentication for a critical function in the input-leapd daemon of Input Leap through version 3.0.3. On Windows, a local low-privileged user can use the unauthenticated IPC interface to execute arbitrary commands as NT AUTHORITY\SYSTEM. The advisory does not assign a CVE or report exploitation in the wild.