Insufficient Authentication Caching in qSnapper by openSUSE
CVE-2026-41048
8.4HIGH
What is CVE-2026-41048?
A flaw in qSnapper, a tool from openSUSE, enables local attackers to exploit insufficient authentication caching between different polkit calls. This vulnerability permits unauthorized users to access functions such as 'restore from snapshot'—actions typically restricted to users with permission to 'delete snapshot' only. The issue is present in all versions before 1.3.3, highlighting the need for an update to resolve this security concern and safeguard against potential misuse.
Affected Version(s)
qSnapper 1.2.1 < 1.3.3
