CVE-2026-41048 Details
Description
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".
A vulnerability in qSnapper prior to version 1.3.3 allows for authentication bypass across different Polkit methods. This issue arises from the incorrect caching of authentication, where once a user is authenticated for a specific action, they are implicitly considered authenticated for other actions as well. This flaw can be exploited by local attackers to gain unauthorized access to certain functionalities, such as restoring files from snapshots, while only being permitted to delete snapshots.
Users can update to qSnapper version 1.3.3, which removes the authentication caching and addresses the Polkit authentication bypass. The update is available on the qSnapper GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1262218 | [email protected] | Issue TrackingThird Party Advisory |
| https://github.com/presire/qSnapper/releases/tag/v1.3.3 | [email protected] | Third Party Advisory |
| https://security.opensuse.org/2026/05/26/qsnapper-dbus-issues.html#issue-auth-caching | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| presire qsnapper | < 1.3.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | Modified Analysis | [email protected] |
| Jul 7, 2026 | CVE Modified | [email protected] |
| Jun 28, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | New CVE Received | [email protected] |