PT-2026-102928 · Barman · Barman

·

CVE-2026-93853

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Barman versions 3.4.0 through 3.20.0
Description Unverified ownership during snapshot backup deletion allows a principal with write access to the backup catalog to trigger the deletion of unrelated cloud snapshots. When a snapshot backup is deleted, either manually or via retention policy, Barman retrieves snapshot identifiers from the backup.info file and sends them to the cloud provider's delete API using its own credentials without verifying ownership. An attacker capable of overwriting backup.info can substitute identifiers to delete any snapshot accessible by Barman's cloud identity on AWS, Microsoft Azure, or Google Cloud. This requires a deployment where the principal writing the backup catalog differs from the identity used by Barman to delete snapshots.
Recommendations Update Barman to version 3.20.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93853

Affected Products

Barman