๐Ÿ” CVE Alert

CVE-2026-41048

UNKNOWN 0.0

Caching of Authentication allows Authentication Bypass in qSnapper

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".

CWE CWE-303
Vendor presire
Product qsnapper
Published Jun 22, 2026
Last Updated Jun 22, 2026
Stay Ahead of the Next One

Get instant alerts for presire qsnapper

Be the first to know when new unknown vulnerabilities affecting presire qsnapper are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

presire / qSnapper
1.2.1 < 1.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
security.opensuse.org: https://security.opensuse.org/2026/05/26/qsnapper-dbus-issues.html#issue-auth-caching github.com: https://github.com/presire/qSnapper/releases/tag/v1.3.3 bugzilla.suse.com: https://bugzilla.suse.com/show_bug.cgi?id=1262218

Credits

Matthias Gerstner of SUSE