Unverified Ownership Vulnerability in Barman Snapshot Backup Deletes
CVE-2026-93853

7.2HIGH

Key Information:

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-93853?

The vulnerability in Barman allows an authorized user to manipulate the backup catalog to delete snapshots from cloud providers without proper verification. It stems from the ability to overwrite the backup.info file, which contains snapshot identifiers. When these identifiers are passed to the delete API, Barman uses its own credentials to execute deletions, and without checking ownership, this can lead to the loss of unrelated snapshots. This exploitation is most impactful in deployments where catalog writing and snapshot deletion permissions are managed by different identities, thus posing a significant risk across popular cloud platforms such as AWS, Microsoft Azure, and Google Cloud.

Affected Version(s)

Barman 3.4.0 < 3.20.1

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mufeed VH of Winfunc
.