CVE-2026-41046 PUBLISHED

path traversal via `config` parameter in qSnapper

Assigner: suse
Reserved: 16.04.2026 Published: 22.06.2026 Updated: 22.06.2026

A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CVSS Score: 7.3

Product Status

Vendor presire
Product qSnapper
Versions Default: unaffected
  • affected from 0 to 1.3.3 (excl.)

Credits

  • Matthias Gerstner of SUSE finder

References

Problem Types

  • CWE-23 Relative path traversal CWE

Impacts

  • CAPEC-17 Using Malicious Files