PT-2026-51333 · Presire+1 · Qsnapper

·

CVE-2026-41046

·

Published

2026-06-22

·

Updated

2026-06-28

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions qSnapper versions prior to 1.3.3
Description A path traversal issue exists when using the configName parameter. This allows a local attacker to utilize malicious configuration files for snapper, which can lead to a denial of service or potential privilege escalation to root. Path traversal is a technique that allows an attacker to access files and directories that are stored outside the web root folder.
Recommendations Update to version 1.3.3 or later. Avoid using the configName parameter until the update is applied.

Exploit

Fix

DoS

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41046

Affected Products

Qsnapper