Security Advisory

CVE-2026-41048

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-22 15:31:14
Last updated 2026-07-07 09:31:37
Assigner suse
CVSS score 8.4
State PUBLISHED

Description

Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".