Junglewise Threat Intelligence

CVE-2026-41048: presire qSnapper authentication bypass via shared m_authenticated flag

CVE-2026-41048 · Severity: info · CVSS 8.4 · Published 2026-06-22

Technologies: Presire qSnapper. Vendors: Presire.

Executive brief

qSnapper, a tool used to manage system backups and snapshots, contains a flaw in how it handles user permissions. An attacker with limited access to a computer could trick the system into granting them higher-level permissions, such as the ability to restore or revert system states, even if they were only authorized to perform minor tasks like deleting a backup. This could lead to unauthorized system changes or data loss.

Technical details

A vulnerability exists in the qSnapper D-Bus daemon (qsnapper-dbus-service) due to the incorrect implementation of an internal authentication cache. The daemon used a shared 'm_authenticated' flag that, once set by a successful Polkit authorization, would bypass subsequent checks for different actions. For example, a user authorized for the 'delete-snapshot' action would implicitly gain authorization for 'rollback-snapshot' because the flag remained set. Additionally, because the flag was shared across the service instance, one user's successful authentication could allow other unprivileged users (including 'nobody') to execute protected D-Bus methods. This has been fixed in version 1.3.3 by removing the internal cache and relying on Polkit's native 'auth_admin_keep' behavior.

Affected products

  • presire qSnapper >= 1.2.1, < 1.3.3

Timeline

  • 2026-04-16: disclosed: Vulnerability identified during SUSE security review.
  • 2026-05-25: patched: Upstream version 1.3.3 released.
  • 2026-06-22: advisory: NVD publication date.

References

Related threats