Security Advisory
CVE-2026-41048
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".