8.6
/ 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards directly to OS execution functions, enabling remote code execution under the service account.
AI Analysis
Command injection vulnerability allowing unauthenticated attackers to execute arbitrary commands via UDP JSON frames
Basic Information
ID
CVE-2026-27182
Source
VulnCheck
Published
Feb 18, 2026 at 20:59
Modified
Feb 18, 2026 at 21:02
Affected Product
Vendor
saturnremote
Product
Saturn Remote Mouse Server
Version
*
Affected Versions
saturnremote Saturn Remote Mouse Server *
CWE Classification
AI Assessment
AI Score
8.6 / 10
AI Severity
High
Vendor
SaturnRemote
Product
Saturn Remote Mouse Server
Version
*