Bug 2461682 (CVE-2026-41477)

Summary: CVE-2026-41477 Deskflow: Deskflow: Privilege escalation and arbitrary code execution via unauthenticated IPC named pipe
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Deskflow. A local unprivileged user can exploit this by interacting with an Inter-Process Communication (IPC) named pipe, which the Deskflow daemon exposes with broad access permissions. The daemon, running with SYSTEM privileges, processes commands without authentication, allowing the user to execute arbitrary commands with SYSTEM privileges. This leads to privilege escalation.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2463196, 2463197    
Bug Blocks:    

Description OSIDB Bzimport 2026-04-24 20:02:02 UTC
Deskflow is a keyboard and mouse sharing app.  In 1.20.0, 1.26.0.134, and earlier, Deskflow daemon runs as SYSTEM and exposes an IPC named pipe with WorldAccessOption enabled. The daemon processes privileged commands without authentication, allowing any local unprivileged user to execute arbitrary commands as SYSTEM. Affects both stable v1.20.0 + and Continuous v1.26.0.134 prerelease.