CVE-2026-41049 Details
Description
Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.
A vulnerability in the qSnapper D-Bus service, affecting versions prior to 1.3.3, allows local attackers to bypass authentication and exploit privileged actions. This issue arises from the incorrect caching of authentication, which enables one user to leverage the authenticated actions of another. The vulnerability is particularly concerning because it can lead to unauthorized access to critical functions, such as restoring files or managing snapshots, with potential implications for system integrity and stability.
Users can upgrade to qSnapper version 1.3.3, which addresses this vulnerability by removing the authentication caching mechanism and implementing proper authorization checks. The update is available through the qSnapper GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1262218 | [email protected] | Third Party Advisory |
| https://github.com/presire/qSnapper/releases/tag/v1.3.3 | [email protected] | Third Party Advisory |
| https://security.opensuse.org/2026/05/26/qsnapper-dbus-issues.html#issue-auth-caching | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| presire qsnapper | < 1.3.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 8, 2026 | Modified Analysis | [email protected] |
| Jul 8, 2026 | CVE Modified | [email protected] |
| Jun 27, 2026 | Initial Analysis | [email protected] |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | New CVE Received | [email protected] |