CVE-2026-41477

Deskflow · Deskflow

Deskflow, an application for sharing keyboards and mice across computers, is vulnerable to a high-severity security flaw that could lead to unauthorized access.

Executive summary

A vulnerability in the Deskflow keyboard and mouse sharing software presents a high-severity risk to cross-computer security and user session integrity.

Vulnerability

This vulnerability affects Deskflow, which enables input sharing between multiple machines. A CVSS score of 7.8 suggests the potential for unauthorized access or session hijacking, likely due to weak authentication or insecure data transmission between the connected client and server machines.

Business impact

The CVSS score of 7.8 indicates a high risk to workstations and connected environments. Exploitation could allow an attacker to hijack a user's mouse and keyboard inputs across multiple machines, potentially leading to unauthorized data entry or command execution on systems the attacker should not control.

Remediation

Immediate Action: Update the Deskflow application to the latest version immediately to patch potential input-sharing vulnerabilities.

Proactive Monitoring: Observe connected workstations for unexpected mouse/keyboard activity or connection attempts from unknown sources.

Compensating Controls: Use encrypted connections and restrict Deskflow communication to trusted, authenticated networks only.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Organizations using keyboard/mouse sharing software should treat this vulnerability seriously. Update all Deskflow instances to ensure that input streams remain secure and authenticated between devices.