Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards directly to OS execution functions, enabling remote code execution under the service account.

Project Subscriptions

Vendors Products
Saturnremote Subscribe
Saturn Remote Mouse Server Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 19 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Saturnremote
Saturnremote saturn Remote Mouse Server
Vendors & Products Saturnremote
Saturnremote saturn Remote Mouse Server

Wed, 18 Feb 2026 21:30:00 +0000

Type Values Removed Values Added
Description Saturn Remote Mouse Server contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending specially crafted UDP JSON frames to port 27000. Attackers on the local network can send malformed packets with unsanitized command data that the service forwards directly to OS execution functions, enabling remote code execution under the service account.
Title Saturn Remote Mouse Server UDP Command Injection RCE
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-19T14:57:25.386Z

Reserved: 2026-02-18T18:13:19.641Z

Link: CVE-2026-27182

cve-icon Vulnrichment

Updated: 2026-02-19T14:56:56.751Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-18T22:16:26.517

Modified: 2026-02-19T15:53:02.850

Link: CVE-2026-27182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-19T10:11:09Z

Weaknesses