CVE-2026-41477
Deskflow · Deskflow
Deskflow, an application for sharing keyboards and mice across computers, is vulnerable to a high-severity security flaw that could lead to unauthorized access.
Executive summary
A vulnerability in the Deskflow keyboard and mouse sharing software presents a high-severity risk to cross-computer security and user session integrity.
Vulnerability
This vulnerability affects Deskflow, which enables input sharing between multiple machines. A CVSS score of 7.8 suggests the potential for unauthorized access or session hijacking, likely due to weak authentication or insecure data transmission between the connected client and server machines.
Business impact
The CVSS score of 7.8 indicates a high risk to workstations and connected environments. Exploitation could allow an attacker to hijack a user's mouse and keyboard inputs across multiple machines, potentially leading to unauthorized data entry or command execution on systems the attacker should not control.
Remediation
Immediate Action: Update the Deskflow application to the latest version immediately to patch potential input-sharing vulnerabilities.
Proactive Monitoring: Observe connected workstations for unexpected mouse/keyboard activity or connection attempts from unknown sources.
Compensating Controls: Use encrypted connections and restrict Deskflow communication to trusted, authenticated networks only.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Organizations using keyboard/mouse sharing software should treat this vulnerability seriously. Update all Deskflow instances to ensure that input streams remain secure and authenticated between devices.