Insufficient Authentication Caching in qSnapper by openSUSE
CVE-2026-41048

8.4HIGH

Key Information:

Vendor

Presire

Status
Vendor
CVE Published:
22 June 2026

What is CVE-2026-41048?

A flaw in qSnapper, a tool from openSUSE, enables local attackers to exploit insufficient authentication caching between different polkit calls. This vulnerability permits unauthorized users to access functions such as 'restore from snapshot'—actions typically restricted to users with permission to 'delete snapshot' only. The issue is present in all versions before 1.3.3, highlighting the need for an update to resolve this security concern and safeguard against potential misuse.

Affected Version(s)

qSnapper 1.2.1 < 1.3.3

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Matthias Gerstner of SUSE
.