Impact
The vulnerability arises from incorrect caching of authentication data between users in the qSnapper D‑Bus service, a flaw classified as CWE‑863. Because authentication state is shared across user sessions, any local attacker can invoke privileged D‑Bus functions after a privileged user has authenticated. The impact is an authentication bypass that permits unauthorized execution of privileged operations within the qSnapper service, effectively enabling local privilege escalation within the application’s context.
Affected Systems
Products affected are qSnapper, specifically the D‑Bus component released by presire. All versions prior to 1.3.3 are vulnerable; the fix introduced in release 1.3.3 removes the caching flaw.
Risk and Exploitability
The CVSS score of 8.4 reflects high severity, while the EPSS score of <1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is local privilege: it requires a trusted process to authenticate first, after which another local user can reuse the authentication token via the caching oversight both privileged and unprivileged users operate, but the potential for service‑wide privilege escalation remains significant.
OpenCVE Enrichment