CVE-2026-93853 - Barman Snapshot Backup Deletion Vulnerability
CVE-2026-93853 - Barman Snapshot Backup Deletion Vulnerability
Date Published: September 29, 2026
A critical vulnerability has been identified in Barman snapshot backup deletion that allows unverified ownership of backup catalog metadata. This flaw enables a malicious actor who can write to the backup catalog to cause Barman to delete unrelated cloud snapshots. 🚨
When a snapshot backup is deleted, either explicitly or through retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and sends them to the cloud provider’s delete API using its own credentials, without verifying the ownership of the snapshots. An attacker who can overwrite backup.info but does not have snapshot delete permissions can replace the identifiers with those of other snapshots, leading to the deletion of any snapshot accessible by Barman’s cloud identity on AWS, Microsoft Azure, or Google Cloud.
Affected Versions
Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue has been resolved in Barman version 3.20.1.
CVE Details
The CVE for this issue, CVE-2026-93853, was reported on September 29, 2026. The vulnerability’s description highlights the risks associated with unverified ownership in Barman snapshot backup deletion.
For more information, you can read the complete article here: Read full article
Stay informed and secure your systems! 🔒