Executive brief
qSnapper, a graphical tool for managing Btrfs system snapshots, contains a vulnerability that allows local users to view sensitive files without proper authorization. By using the "snapshot diff" feature, an unprivileged user can compare different versions of system files, such as password databases or private configuration files, which are normally restricted. This could lead to the exposure of administrative credentials or other private system data.
Technical details
A missing authentication vulnerability (CWE-306) exists in qSnapper before version 1.3.3 within its D-Bus service. The 'list-snapshots' Polkit action was incorrectly applied to sensitive methods including GetFileChanges, GetFileDiffAndDetails, GetFileChangesBetween, and GetFileDiffBetween, allowing locally logged-in users to execute them without administrative credentials. An attacker can exploit this to perform diff operations on restricted files (e.g., /etc/shadow) across different snapshots, effectively bypassing filesystem permissions to leak sensitive data. The issue was resolved in version 1.3.3 by introducing a new 'view-diff' Polkit action that requires administrative authentication.
Affected products
- presire qSnapper before 1.3.3
Timeline
- 2026-04-10: disclosed: Initial discovery and report by SUSE security team
- 2026-05-25: patched: Upstream release 1.3.3 published with fixes
- 2026-06-22: advisory: CVE-2026-41047 published to NVD