CVE-2026-96538: CWE-862 Missing Authorization in EnterpriseDB WarehousePG
WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.
AI Analysis
Technical Summary
WarehousePG 7.x before 7.6.0-WHPG suffers from a missing authorization vulnerability in built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are callable by any authenticated database role without requiring GRANT permissions because the REVOKE protections from the contrib/adminpack were not applied after merging with PostgreSQL 12. Non-superusers can manipulate files in data and log directories, including appending malicious directives to postgresql.auto.conf, enabling arbitrary code execution as the postgres OS user upon server restart or reload. WarehousePG 6.x is unaffected as it enforces superuser checks internally.
Potential Impact
An attacker with any authenticated database role can exploit this vulnerability to manipulate critical files within the data and log directories. This includes creating, overwriting, renaming, and deleting files, as well as enumerating log files. By appending malicious configuration directives to postgresql.auto.conf, the attacker can achieve arbitrary code execution as the postgres operating system user after the next server restart or configuration reload. This represents a high-severity risk due to the potential for full system compromise.
Mitigation Recommendations
No explicit patch or fix is stated in the provided data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated database roles to trusted users only. Monitor vendor communications for official patches or updates addressing this missing authorization vulnerability.
CVE-2026-96538: CWE-862 Missing Authorization in EnterpriseDB WarehousePG
Description
WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.
CVSS v4.0
Score 8.7high
Affected software
EnterpriseDB
WarehousePG
pkg:github/warehouse-pg/warehouse-pgRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
WarehousePG 7.x before 7.6.0-WHPG suffers from a missing authorization vulnerability in built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are callable by any authenticated database role without requiring GRANT permissions because the REVOKE protections from the contrib/adminpack were not applied after merging with PostgreSQL 12. Non-superusers can manipulate files in data and log directories, including appending malicious directives to postgresql.auto.conf, enabling arbitrary code execution as the postgres OS user upon server restart or reload. WarehousePG 6.x is unaffected as it enforces superuser checks internally.
Potential Impact
An attacker with any authenticated database role can exploit this vulnerability to manipulate critical files within the data and log directories. This includes creating, overwriting, renaming, and deleting files, as well as enumerating log files. By appending malicious configuration directives to postgresql.auto.conf, the attacker can achieve arbitrary code execution as the postgres operating system user after the next server restart or configuration reload. This represents a high-severity risk due to the potential for full system compromise.
Mitigation Recommendations
No explicit patch or fix is stated in the provided data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict authenticated database roles to trusted users only. Monitor vendor communications for official patches or updates addressing this missing authorization vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- EDB
- Date Reserved
- 2026-09-23T11:52:41.065Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aba81c1f7a7c54106d44fde
Added to database: 09/28/2026, 15:03:29 UTC
Last enriched: 09/28/2026, 15:17:43 UTC
Last updated: 09/29/2026, 01:57:22 UTC
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.