CVE-2026-96538 Details
Description
WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.
A missing authorization vulnerability has been identified in WarehousePG (WHPG) version 7.x prior to 7.6.0-WHPG. The vulnerability exists in several built-in server-side file functions: pg_file_write, pg_file_rename, pg_file_unlink, and pg_logdir_ls. These functions can be executed by any authenticated database role without the need for explicit permissions. The issue arises because the privilege revocation applied in contrib/adminpack was not carried over to WHPG core, allowing non-superusers to manipulate files in the data and log directories. This could be exploited to execute arbitrary code as the postgres operating system user by modifying the postgresql.auto.conf file, with the changes taking effect on the next server restart or configuration reload. Additionally, the pg_logdir_ls function could be used to list log file names.
Users are advised to upgrade to WarehousePG version 7.6.0 or later. For immediate mitigation on existing clusters, revoke execute permissions on the vulnerable functions from the public role and restore access only for administrators who need it. This stopgap measure must be reapplied on every database and does not protect clusters created after being applied unless also run against template1.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/warehouse-pg/warehouse-pg/pull/305 | EnterpriseDB Corporation | Issue TrackingVendor |
| https://www.enterprisedb.com/docs/security/advisories/cve202696538 | EnterpriseDB Corporation | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | EnterpriseDB Corporation |
Affected Products
| Product | Versions |
|---|---|
| WarehousePG | >= 7, <= 7.5.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | EnterpriseDB Corporation |
Volerion