CVE-2026-41045 PUBLISHED

Weak polkit authentication check in qSnapper

Assigner: suse
Reserved: 16.04.2026 Published: 22.06.2026 Updated: 22.06.2026

A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 8.1

Product Status

Vendor presire
Product qSnapper
Versions Default: unaffected
  • affected from 0 to 1.3.3 (excl.)

Credits

  • Matthias Gerstner of SUSE finder

References

Problem Types

  • CWE-367 Time-of-check time-of-use (TOCTOU) race condition CWE

Impacts

  • CAPEC-115 Authentication Bypass