CVE-2026-41049
Last modified
CVE-2026-41049 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Undergoing Analysis
Frequently Asked Questions
What is CVE-2026-41049?
How severe is CVE-2026-41049?
How do I fix CVE-2026-41049?
Are you affected by CVE-2026-41049?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
