๐Ÿ” CVE Alert

CVE-2026-93853

UNKNOWN 0.0

Barman snapshot backup deletion trusts unverified backup catalog metadata

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and passes them to the cloud provider's delete API using Barman's own credentials, without verifying that the snapshots belong to that backup. An attacker who can overwrite backup.info but lacks snapshot delete permissions can substitute the identifiers of other snapshots, causing Barman to delete any snapshot its cloud identity can reach on AWS, Microsoft Azure, or Google Cloud. Exploitation requires a deployment where the principal that writes the backup catalog is separate from the identity Barman uses to delete snapshots. Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue is fixed in Barman 3.20.1.

CWE CWE-283
Vendor enterprisedb
Product barman
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for enterprisedb barman

Be the first to know when new unknown vulnerabilities affecting enterprisedb barman are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

EnterpriseDB / Barman
3.4.0 < 3.20.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
enterprisedb.com: https://www.enterprisedb.com/docs/security/advisories/cve202693853/

Credits

Mufeed VH of Winfunc