Security Advisory

CVE-2026-41046

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-22 15:20:30
Last updated 2026-06-22 16:23:53
Assigner suse
CVSS score 7.3
State PUBLISHED

Description

A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.