A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.
https://security.opensuse.org/2026/05/26/qsnapper-dbus-issues.html#issue-polkit-bypass