Unverified Ownership Vulnerability in Barman Snapshot Backup Deletes
CVE-2026-93853
7.2HIGH
What is CVE-2026-93853?
The vulnerability in Barman allows an authorized user to manipulate the backup catalog to delete snapshots from cloud providers without proper verification. It stems from the ability to overwrite the backup.info file, which contains snapshot identifiers. When these identifiers are passed to the delete API, Barman uses its own credentials to execute deletions, and without checking ownership, this can lead to the loss of unrelated snapshots. This exploitation is most impactful in deployments where catalog writing and snapshot deletion permissions are managed by different identities, thus posing a significant risk across popular cloud platforms such as AWS, Microsoft Azure, and Google Cloud.
Affected Version(s)
Barman 3.4.0 < 3.20.1
