PT-2026-102928 · Barman · Barman
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Barman versions 3.4.0 through 3.20.0
Description
Unverified ownership during snapshot backup deletion allows a principal with write access to the backup catalog to trigger the deletion of unrelated cloud snapshots. When a snapshot backup is deleted, either manually or via retention policy, Barman retrieves snapshot identifiers from the
backup.info file and sends them to the cloud provider's delete API using its own credentials without verifying ownership. An attacker capable of overwriting backup.info can substitute identifiers to delete any snapshot accessible by Barman's cloud identity on AWS, Microsoft Azure, or Google Cloud. This requires a deployment where the principal writing the backup catalog differs from the identity used by Barman to delete snapshots.Recommendations
Update Barman to version 3.20.1.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Barman