https://seclists.org/oss-sec/2026/q3/938: [NotCVE-2026-0015] Input Leap through 3.0.3 input-leapd Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
Published Sep 25, 2026
·Updated
Affected Software
1 affected component
Input Leap Input Leap>=2.4.0<=3.0.3
Frequently Asked Questions
1
Which deployments are susceptible?
Input Leap on Windows is affected from version 2.4.0 through 3.0.3 when input-leapd is registered as a service. The issue applies to the daemon's listener on 127.0.0.1:24801.
2
What access does an attacker need?
An attacker needs local access as a low-privileged Windows user. No authentication, user interaction, or network access is required; the attacker can send a single IPC command to the localhost listener.
3
What is the impact after successful exploitation?
A local low-privileged user can execute arbitrary commands as NT AUTHORITY\SYSTEM. The submitted command persists and is run again after a service restart or system reboot.
4
Is a vendor fix available?
No fixed version exists or is expected. The Input Leap repository was archived read-only on 26 July 2026.