[NotCVE-2026-0015] Input Leap through 3.0.3 input-leapd Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
Input Leap through 3.0.3 lets a local Windows user run commands as SYSTEM via unauthenticated IPC.
NotCVE-2026-0015 describes missing authentication for a critical function in the input-leapd daemon of Input Leap through version 3.0.3. On Windows, a local low-privileged user can use the unauthenticated IPC interface to execute arbitrary commands as NT AUTHORITY\SYSTEM. The advisory does not assign a CVE or report exploitation in the wild.
- input-leapd IPC function lacks authentication through version 3.0.3.
- A local low-privileged Windows user can run commands as SYSTEM.
- Tracked as NotCVE-2026-0015, which is not a CVE identifier.
Posted by advisories on Sep 26 ---------------------------------------------------------------------------- NotCVE Advisory — NotCVE-2026-0015 ---------------------------------------------------------------------------- [-] Summary: Missing authentication for a critical function in the input-leapd daemon of Input Leap, the open-source keyboard and mouse sharing tool, allows a local, low-privileged user on Windows to execute arbitrary commands as NT AUTHORITY\SYSTEM by...
This source does not provide full text. Read it at seclists.org.