CVE-2026-41477Disclosure(deskflow / deskflow)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch deskflow deskflow systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with WorldAccessOption enabled. The daemon processes privileged commands without authentication, allowing any local unprivileged user to execute arbitrary commands as SYSTEM. Affects both stable v1.20.0 + and Continuous v1.26.0.134 prerelease.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • deskflow

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
deskflow

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-06: 1Patch / Workaround · 2026-05-06: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 104-2404-2505-06
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-241
Disclosure1
2026-04-251
Disclosure1
2026-05-061
Patch1
Full discourse3 posts
  • Wessel Hissink@WesSec_
    Patch

    Not many sites reporting on a LPE (CVE-2026-41477) for Deskflow, Deskflow is used in Synergy, Software to share mouse/keyboard across devices. Patch is available, as is a poc. Malicious activity is easily detectable, but defender doesn't flag it. KQL: https://gist.github.com/WesSec/b91beeb14ec682292de629a239362722

    Post summary

    The post highlights a local privilege escalation flaw in Deskflow, noting that a patch and PoC are available, and that malicious activity can be detected via a provided detection query.

    0001098
    235 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41477 Local Privilege Escalation in Deskflow via Unauthenticated IPC Named Pipe https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41477

    Post summary

    A brief disclosure announces a local privilege escalation flaw in Deskflow involving an unauthenticated IPC named pipe.

    0001056
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41477 Deskflow is a keyboard and mouse sharing app. In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with WorldAccessOption… https://www.cve.org/CVERecord?id=CVE-2026-41477

    Post summary

    The CVE reports a privilege escalation flaw in Deskflow, where the daemon runs as SYSTEM and exposes a world-accessible IPC named pipe; no PoC, exploit, or active exploitation details are cited.

    0000060
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdeskflowdeskflow---

Explore more