SUSE disclosed four vulnerabilities in qSnapper’s privileged root D-Bus service, affecting versions through 1.3.2 and tracked as CVE-2026-41045 through CVE-2026-41048. The flaws include a Polkit race-condition authentication bypass, a path traversal issue in the configName parameter, information disclosure through snapshot diff methods, and unsafe authentication caching that could allow one user’s authorization to be reused by another. SUSE said some bug chains could lead to full local root exploitation, while other impacts include denial of service, arbitrary file operations, and exposure of sensitive content such as diffs involving /etc/shadow.
Upstream released qSnapper 1.3.3 with fixes that change Polkit subject handling, validate configName, remove authentication caching, restrict diff access behind a new view-diff Polkit action, remove the unauthenticated Quit method, and harden log file permissions. SUSE also acknowledged additional defense-in-depth weaknesses in file restore logic that could support symlink-based privilege escalation or arbitrary file operations, but said those issues were not assigned separate CVEs and will be addressed later through open development.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
SUSE disclosed multiple local security flaws in qSnapper's privileged D-Bus service affecting versions up to 1.3.2, including authentication bypass, path traversal, information disclosure, and potential local root exploitation. Upstream coordinated disclosure, accepted CVE assignments CVE-2026-41045 through CVE-2026-41048, and released fixes in qSnapper 1.3.3 on 2026-05-26.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourcesecurity.opensuse.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.