CVE-2026-41046
EUVD-2026-3826322.06.2026, 16:16
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| presire | qsnapper | 𝑥 < 1.3.3 |
𝑥
= Vulnerable software versions