[NotCVE-2026-0015] Input Leap through 3.0.3 input-leapd Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
Input Leap through 3.0.3 lets a local Windows user run commands as SYSTEM via unauthenticated IPC.
An oss-security advisory labeled NotCVE-2026-0015 says Input Leap through version 3.0.3 lacks authentication on a critical function in the input-leapd daemon. A local, low-privileged Windows user can use that unauthenticated IPC interface to execute arbitrary commands as NT AUTHORITY\SYSTEM. The notice describes a local privilege escalation and does not report observed exploitation or assign a standard CVE identifier.
- Input Leap through 3.0.3 on Windows is affected.
- input-leapd exposes an unauthenticated IPC command function.
- A local low-privilege user can run commands as SYSTEM.
- Published as NotCVE-2026-0015; no standard CVE or exploitation report.
Posted by advisories on Sep 25 ---------------------------------------------------------------------------- NotCVE Advisory — NotCVE-2026-0015 ---------------------------------------------------------------------------- [-] Summary: Missing authentication for a critical function in the input-leapd daemon of Input Leap, the open-source keyboard and mouse sharing tool, allows a local, low-privileged user on Windows to execute arbitrary commands as NT AUTHORITY\SYSTEM by...
This source does not provide full text. Read it at seclists.org.