VYPR

qSnapper

by Presire

CVEs (5)

  • CVE-2026-41045HigJun 22, 2026
    risk 0.53cvss 8.1epss 0.00

    A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.

  • CVE-2026-41046HigJun 22, 2026
    risk 0.47cvss 7.3epss 0.00

    A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.

  • CVE-2026-41049HigJun 22, 2026
    risk 0.46cvss 7.1epss 0.00

    Incorrect caching of authentication between different users of the  qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.

  • CVE-2026-41048HigJun 22, 2026
    risk 0.46cvss 7.1epss 0.00

    Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".

  • CVE-2026-41047MedJun 22, 2026
    risk 0.36cvss 5.5epss 0.00

    Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.