Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93853— Barman snapshot backup deletion trusts unverified backup catalog metadata

Quick assessment

Affected
EnterpriseDB Barman
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Barman 快照备份删除中存在未经验证的所有权问题,允许能够写入备份目录的主体导致 Barman 删除不相关的云快照。当快照备份被删除时(无论是显式删除还是通过保留策略强制执行),Barman 会从 文件中读取快照标识符,并使用 Barman 自身凭据将这些标识符传递给云提供商的删除 API,但在此过程中并未验证这些快照是否属于该备份。攻击者若能够覆盖 文件,但缺乏快照删除权限,则可以替换其他快照的标识符,从而导致 Barman 使用其云身份可以访问的任何 AWS、Microsoft Azure 或 Google

CVSS 7.2 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93853

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Barman snapshot backup deletion trusts unverified backup catalog metadata
Source: CVE Program / CVE List V5
Vulnerability Description
Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and passes them to the cloud provider's delete API using Barman's own credentials, without verifying that the snapshots belong to that backup. An attacker who can overwrite backup.info but lacks snapshot delete permissions can substitute the identifiers of other snapshots, causing Barman to delete any snapshot its cloud identity can reach on AWS, Microsoft Azure, or Google Cloud. Exploitation requires a deployment where the principal that writes the backup catalog is separate from the identity Barman uses to delete snapshots. Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue is fixed in Barman 3.20.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
未经验证的属主
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
EnterpriseDB Barman 3.4.0 ~ 3.20.1 -

II. Public POCs for CVE-2026-93853

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93853

请登录查看更多情报信息。

Other References for CVE-2026-93853 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93853

No comments yet


Leave a comment