Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-96538 Details

ANALYZED


This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.

Description

WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/warehouse-pg/warehouse-pg/pull/305 EnterpriseDB CorporationIssue TrackingVendor
https://www.enterprisedb.com/docs/security/advisories/cve202696538 EnterpriseDB CorporationAdvisoryRemedy

Weakness Enumeration

CWE-IDCWE NameSource
CWE-862Missing AuthorizationEnterpriseDB Corporation

Affected Products

ProductVersions
WarehousePG
>= 7, <= 7.5.0

CPE

  • No CPEs found in CPE dictionary for this product.

Remediation

  • Upgrade: 7.6.0moderate effort
  • Mitigation:low effort

    Execute the following commands as a superuser in every connectable database (including all user databases, "postgres", and "template1"): REVOKE EXECUTE ON FUNCTION pg_file_write(text,text,boolean) FROM public; REVOKE EXECUTE ON FUNCTION pg_file_rename(text,text,text) FROM public; REVOKE EXECUTE ON FUNCTION pg_file_unlink(text) FROM public; REVOKE EXECUTE ON FUNCTION pg_logdir_ls() FROM public; GRANT EXECUTE ON FUNCTION pg_file_write(text,text,boolean) TO pg_write_server_files; GRANT EXECUTE ON FUNCTION pg_file_rename(text,text,text) TO pg_write_server_files; GRANT EXECUTE ON FUNCTION pg_file_unlink(text) TO pg_write_server_files; GRANT EXECUTE ON FUNCTION pg_logdir_ls() TO pg_read_server_files;

Change History

2 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-96538
NVD Published Date:
Sep 28, 2026
NVD Last Modified:
Sep 30, 2026
Source:
EnterpriseDB Corporation
CVE-2026-96538 Details - Not Deferred