CVE-2026-93853
Received Received - Intake

Barman Unverified Ownership Leads to Unauthorized Cloud Snapshot Deletion

Vulnerability report for CVE-2026-93853, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: EnterpriseDB Corporation

Description

Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and passes them to the cloud provider's delete API using Barman's own credentials, without verifying that the snapshots belong to that backup. An attacker who can overwrite backup.info but lacks snapshot delete permissions can substitute the identifiers of other snapshots, causing Barman to delete any snapshot its cloud identity can reach on AWS, Microsoft Azure, or Google Cloud. Exploitation requires a deployment where the principal that writes the backup catalog is separate from the identity Barman uses to delete snapshots. Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue is fixed in Barman 3.20.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-283 The product does not properly verify that a critical resource is owned by the proper entity.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Barman, a backup management tool, where an attacker who can write to the backup catalog can trick Barman into deleting unrelated cloud snapshots. When Barman deletes a snapshot, it reads identifiers from a backup.info file and sends them to the cloud provider's delete API without verifying ownership. An attacker can replace these identifiers with those of other snapshots, causing Barman to delete any accessible snapshot on AWS, Azure, or Google Cloud.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized modifications to backup.info files and verifying snapshot ownership. Inspect backup.info files for unexpected snapshot IDs and compare them with actual cloud snapshots. Review Barman logs for deletion operations that do not match expected backup snapshots.

Impact Analysis

If exploited, this vulnerability could lead to unauthorized deletion of critical cloud snapshots, causing data loss or service disruption. Organizations using Barman for backups in cloud environments are at risk, especially if the backup catalog writer and snapshot deletion identity are separate. The impact includes potential downtime, loss of important data, and operational disruptions.

Compliance Impact

This vulnerability could violate compliance requirements by causing unauthorized data deletion, which may breach data integrity and availability principles in GDPR and HIPAA. Loss of backup snapshots could result in non-compliance with retention policies, leading to legal and regulatory penalties.

Mitigation Strategies

Upgrade Barman to version 3.20.1 or later immediately. Ensure the principal writing to backup.info does not have permissions to delete snapshots. Restrict access to backup.info files and monitor for unauthorized changes. Verify snapshot ownership before deletion operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93853. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart