Description
Incorrect caching of authentication between different users of the  qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.
Published: 2026-06-22
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from incorrect caching of authentication data between users in the qSnapper D‑Bus service, a flaw classified as CWE‑863. Because authentication state is shared across user sessions, any local attacker can invoke privileged D‑Bus functions after a privileged user has authenticated. The impact is an authentication bypass that permits unauthorized execution of privileged operations within the qSnapper service, effectively enabling local privilege escalation within the application’s context.

Affected Systems

Products affected are qSnapper, specifically the D‑Bus component released by presire. All versions prior to 1.3.3 are vulnerable; the fix introduced in release 1.3.3 removes the caching flaw.

Risk and Exploitability

The CVSS score of 8.4 reflects high severity, while the EPSS score of <1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is local privilege: it requires a trusted process to authenticate first, after which another local user can reuse the authentication token via the caching oversight both privileged and unprivileged users operate, but the potential for service‑wide privilege escalation remains significant.

Generated by OpenCVE AI on August 2, 2026 at 01:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade qSnapper to version 1.3.3 or newer, which removes the authentication caching flaw.
  • If upgrading is not immediately feasible, eliminate or disable privileged accounts that can authenticate to qSnapper to prevent the caching flaw from being triggered.
  • Configure D‑Bus policies to restrict access to the qSnapper service to the intended users only, ensuring that other users cannot invoke privileged methods.

Generated by OpenCVE AI on August 2, 2026 at 01:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-303 CWE-863

Tue, 23 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Presire
Presire qsnapper
Vendors & Products Presire
Presire qsnapper

Mon, 22 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 22 Jun 2026 15:45:00 +0000

Type Values Removed Values Added
Description Incorrect caching of authentication between different users of the  qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.
Title Caching of Authentication allows Authentication Bypass between users in qSnapper
Weaknesses CWE-303
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Presire Qsnapper
cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-07-08T05:55:01.962Z

Reserved: 2026-04-16T13:37:50.679Z

Link: CVE-2026-41049

cve-icon Vulnrichment

Updated: 2026-06-22T16:25:26.347Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T01:45:06Z

Weaknesses