# CVE-2026-65832

## Summary

- **CVE ID:** CVE-2026-65832
- **Severity:** HIGH
- **CVSS Score:** 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H)
- **CWE:** CWE-125, CWE-129
- **Published:** Aug 17, 2026
- **Last Modified:** Aug 18, 2026

## Description

Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp so that the value following a modifier option poisons m_modifierTranslationTable, after which ServerProxy::translateKey() or ServerProxy::translateModifierMask() indexes the seven-row s_translationTable or s_masks arrays out of bounds, disclosing four bytes at an attacker-selected relative offset or crashing the connected client; an odd option count also causes an out-of-bounds OptionsList read. This issue is fixed in continuous build 1.26.0.299.

## Affected Products

- deskflow — deskflow (< 1.26.0.299)

## References

- [CNA](https://github.com/deskflow/deskflow/security/advisories/GHSA-8rcq-7w87-h64j)
- [CNA](https://github.com/deskflow/deskflow/commit/205a3c803e5298d56683660736ec1a41b671b56e)
- [CNA](https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.30%
- **EPSS Percentile:** 22.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._