Input Leap through 3.0.3: flaw allows escalation to SYSTEM
NotCVE-2026-0015 reports that an unauthenticated critical function in the input-leapd daemon may let a low-privilege local Windows user run commands as NT AUTHORITY\SYSTEM.
An advisory published on September 25, 2026, in the oss-sec feed and identified as NotCVE-2026-0015 reports a flaw affecting Input Leap through version 3.0.3. The open-source program shares a keyboard and mouse; according to the summary, an unauthenticated critical function in the input-leapd daemon lets a low-privilege local Windows user run arbitrary commands as NT AUTHORITY\SYSTEM. The supplied publication is an automatic translation and its text is truncated, so it does not provide further technical details or a fix here.
To consult and verify the case, find advisory NotCVE-2026-0015 in the oss-sec feed archive and check the original, affected-version scope, and any remediation guidance before acting. If using AI to summarize the advisory or prepare an internal analysis, avoid entering confidential organizational data and validate technical conclusions against the publication and project documentation.