Missing Authorization Vulnerability in WarehousePG by EDB
CVE-2026-96538

8.7HIGH

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-96538?

WarehousePG versions prior to 7.6.0-WHPG are vulnerable to a missing authorization flaw that allows authenticated database users to execute server-side file functions without proper controls. Functions such as pg_file_write, pg_file_rename, and pg_file_unlink can be exploited by non-superuser roles, enabling them to manipulate files within the database's data and log directories. Additionally, the pg_logdir_ls function allows attackers to list log file names. This vulnerability can lead to arbitrary code execution by altering critical configuration files, such as postgresql.auto.conf, during server restarts or reloads.

Affected Version(s)

WarehousePG 7.0.0 < 7.6.0-WHPG

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.