Local Information Disclosure Vulnerability in qSnapper by openSUSE
CVE-2026-41047

6.9MEDIUM

Key Information:

Vendor

Presire

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-41047?

A vulnerability in qSnapper allows a local attacker to exploit the snapshot diff functionality, gaining unauthorized access to sensitive information that should be protected. This issue arises due to the absence of required authentication checks in earlier versions, specifically before 1.3.3, making it possible for attackers with local access to the system to view data that is otherwise meant to be restricted.

Affected Version(s)

qSnapper 0 < 1.3.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthias Gerstner of SUSE
.