CVE 8.6 HIGH

Saturn Remote Mouse Server UDP Command Injection RCE_CVE-2026-27182

8.6 / 10
HIGH
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards directly to OS execution functions, enabling remote code execution under the service account.

AI Analysis

Command injection vulnerability allowing unauthenticated attackers to execute arbitrary commands via UDP JSON frames

Basic Information

ID CVE-2026-27182
Source VulnCheck
Published Feb 18, 2026 at 20:59
Modified Feb 18, 2026 at 21:02

Affected Product

Vendor saturnremote
Product Saturn Remote Mouse Server
Version *
Affected Versions saturnremote Saturn Remote Mouse Server *

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor SaturnRemote
Product Saturn Remote Mouse Server
Version *

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.