Skip to main content

CVE-2026-93853: CWE-283 Unverified Ownership in EnterpriseDB Barman

0
High
VulnerabilityCVE-2026-93853cvecve-2026-93853cwe-283
Published: 09/29/2026 (09/29/2026, 20:55:51 UTC)
Source: CVE Database V5
Vendor/Project: EnterpriseDB
Product: Barman

Description

Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and passes them to the cloud provider's delete API using Barman's own credentials, without verifying that the snapshots belong to that backup. An attacker who can overwrite backup.info but lacks snapshot delete permissions can substitute the identifiers of other snapshots, causing Barman to delete any snapshot its cloud identity can reach on AWS, Microsoft Azure, or Google Cloud. Exploitation requires a deployment where the principal that writes the backup catalog is separate from the identity Barman uses to delete snapshots. Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue is fixed in Barman 3.20.1.

CVSS v4.0

Score 7.2high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
High
Subsq. Availability
High
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H

Affected software

EnterpriseDB

Barman

Affected versions
>=3.4.0 <3.20.1
GitHub Actionsmore threats →cve
Barman
pkg:github/Barman
Affected versions
>=3.4.0 <3.20.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 21:21:19 UTC

Technical Analysis

This vulnerability arises because Barman does not verify that snapshot identifiers read from the backup.info file during backup deletion actually belong to the backup being deleted. An attacker who can overwrite the backup.info file but lacks direct snapshot delete permissions can substitute identifiers of other snapshots. Barman then uses its own cloud credentials to delete these unrelated snapshots via the cloud provider's delete API. Exploitation requires that the principal writing the backup catalog is distinct from the identity Barman uses to delete snapshots. Affected versions include Barman >=3.4.0 and <3.20.1, with the fix implemented in 3.20.1.

Potential Impact

An attacker with write access to the backup catalog can cause Barman to delete arbitrary cloud snapshots accessible by Barman's cloud identity, potentially leading to unintended data loss across AWS, Azure, or Google Cloud environments. This can disrupt backup integrity and availability.

Mitigation Recommendations

A patch is available and the issue is fixed in Barman version 3.20.1. Users should upgrade to version 3.20.1 or later to remediate this vulnerability. Since this is a cloud-hosted service component, the vendor manages remediation through the patch release. No additional mitigations are specified.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
EDB
Date Reserved
2026-09-18T18:52:15.463Z
Cvss Version
4.0
State
PUBLISHED
Is Cloud Service
true

Threat ID: 6abc287d680226ef6848d2d5

Added to database: 09/29/2026, 21:07:09 UTC

Last enriched: 09/29/2026, 21:21:19 UTC

Last updated: 09/30/2026, 03:38:31 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses