[NotCVE-2026-0015] Input Leap through 3.0.3 input-leapd Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
Input Leap through 3.0.3 lets a local Windows user run commands as SYSTEM via unauthenticated IPC.
An oss-security advisory labeled NotCVE-2026-0015 says Input Leap through version 3.0.3 lacks authentication on a critical function in the input-leapd daemon. A local, low-privileged Windows user can use that unauthenticated IPC interface to execute arbitrary commands as NT AUTHORITY\SYSTEM. The notice describes a local privilege escalation and does not report observed exploitation or assign a standard CVE identifier.
47