{"id":"CVE-2026-41048","title":"Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like \"restore from snapshot\" even if only allowed to do \"delete snapshot\".","summary":"Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like \"restore from snapshot\" even if only allowed to do \"delete snapshot\".","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","cwe":["CWE-863","CWE-863"],"vendor":"presire","product":"qsnapper","affected":["qsnapper < 1.3.3"],"patched":["qsnapper 1.3.3"],"published":"2026-06-22","updated":"2026-07-07","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-41048","references":[{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1262218","label":"meissner@suse.de"},{"url":"https://github.com/presire/qSnapper/releases/tag/v1.3.3","label":"meissner@suse.de"},{"url":"https://security.opensuse.org/2026/05/26/qsnapper-dbus-issues.html#issue-auth-caching","label":"meissner@suse.de"}],"tags":["nvd"],"epss":0.00178,"epssPercentile":0.076,"ingestedAt":"2026-07-07T10:52:44.327Z","slug":"CVE-2026-41048","body":"## Overview\n\nIncorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like \"restore from snapshot\" even if only allowed to do \"delete snapshot\".\n\n## Affected\n\n- `qsnapper < 1.3.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `qsnapper 1.3.3`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}