CVE-2026-96538
Received Received - Intake

Missing Authorization in WarehousePG File Functions

Vulnerability report for CVE-2026-96538, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: EnterpriseDB Corporation

Description

WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
whpg warehousepg to 7.6.0-WHPG (exc)
whpg warehousepg 6.x
warehouse_pg warehouse_pg to 7.5.0 (inc)
warehouse_pg warehouse_pg 7.6.0
postgresql postgresql *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-96538 is a missing authorization vulnerability in WarehousePG (WHPG) 7.x versions before 7.6.0. It affects server-side file functions pg_file_write, pg_file_rename, pg_file_unlink, and pg_logdir_ls, which any authenticated database role can execute without explicit permissions. This occurs because privilege revocations from contrib/adminpack were not applied when these functions were merged into WHPG core. A non-superuser can manipulate files in data and log directories, including modifying configuration files to achieve code execution as the postgres OS user.

Detection Guidance

Check if any non-superuser roles have access to the vulnerable functions by running: SELECT grantee, privilege_type FROM information_schema.role_table_grants WHERE table_name IN ('pg_file_write', 'pg_file_rename', 'pg_file_unlink', 'pg_logdir_ls');

Verify WHPG version with: SELECT version(); and check if it is 7.x before 7.6.0.

Impact Analysis

An attacker with database access could create, overwrite, rename, or delete files in critical directories. They could append malicious configuration directives to postgresql.auto.conf, such as shared_preload_libraries or archive_command, leading to arbitrary code execution when the server restarts or reloads configuration. They could also enumerate log files via pg_logdir_ls.

Compliance Impact

This vulnerability could lead to unauthorized file access or modification, violating data integrity and confidentiality requirements in GDPR and HIPAA. Unauthorized code execution may result in data breaches or loss, triggering compliance violations and potential regulatory penalties.

Mitigation Strategies

Upgrade to WarehousePG 7.6.0 or later immediately. As a temporary fix, revoke PUBLIC EXECUTE permissions on the vulnerable functions in every database including template1 using: REVOKE EXECUTE ON FUNCTION pg_file_write(text,text,bool) FROM PUBLIC; REVOKE EXECUTE ON FUNCTION pg_file_rename(text,text,text) FROM PUBLIC; REVOKE EXECUTE ON FUNCTION pg_file_unlink(text) FROM PUBLIC; REVOKE EXECUTE ON FUNCTION pg_logdir_ls() FROM PUBLIC;

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96538. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart