CVE-2026-41049
- EPSS 0.14%
- Veröffentlicht 22.06.2026 15:32:59
- Zuletzt bearbeitet 08.07.2026 15:42:08
Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.
CVE-2026-41048
- EPSS 0.13%
- Veröffentlicht 22.06.2026 15:31:14
- Zuletzt bearbeitet 07.07.2026 18:51:15
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".
CVE-2026-41047
- EPSS 0.15%
- Veröffentlicht 22.06.2026 15:25:12
- Zuletzt bearbeitet 07.07.2026 18:51:29
Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.
CVE-2026-41046
- EPSS 0.19%
- Veröffentlicht 22.06.2026 15:20:30
- Zuletzt bearbeitet 28.06.2026 00:17:15
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.
- EPSS 0.14%
- Veröffentlicht 22.06.2026 15:16:37
- Zuletzt bearbeitet 28.06.2026 00:10:33
A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.