Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-96538: WarehousePG lets regular users modify server files

CVE-2026-96538 · published 4 days ago
Summary

In WarehousePG version 7.x before 7.6.0, any logged‑in database user can run built‑in functions to write, rename, delete, or list files in the database’s data and log folders. This means a non‑administrator could change configuration files or remove logs, potentially allowing code to run with the database’s operating system account. Upgrade to WarehousePG 7.6.0 or later, or restrict these functions to trusted administrators, to eliminate the risk.

What to do
  • Update enterprisedb warehousepg to version 7.6.0-WHPG or later.
Affected software
VendorProductAffected versions
enterprisedb warehousepg < 7.6.0-WHPG
Original advisory text
WarehousePG pg_file_write/pg_file_rename/pg_file_unlink/pg_logdir_ls privilege escalation
WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-862Missing Authorization
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-96538 · MITRE
Track software like this
Free during beta