CVE-2026-96538

Source
https://cve.org/CVERecord?id=CVE-2026-96538
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-96538.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-96538
Published
2026-09-28T15:17:25Z
Modified
2026-10-02T08:13:39Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.

References

Affected packages

Git / github.com/warehouse-pg/warehouse-pg

Affected ranges

Type
GIT
Repo
https://github.com/warehouse-pg/warehouse-pg
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "7.x"
        },
        {
            "fixed":  "7.6.0-WHPG"
        }
    ],
    "source":  "DESCRIPTION"
}

Affected versions

5.*
5.0.0-alpha.0
5.0.0-alpha.1
5.0.0-alpha.2
5.0.0-alpha.3
5.0.0-alpha.4
5.0.0-alpha.5
5.0.0-alpha.6
5.0.0-alpha.7
5.0.0-alpha.8
5.0.0-beta.1
5.0.0-beta.10
5.0.0-beta.2
5.0.0-beta.3
5.0.0-beta.4
5.0.0-beta.5
5.0.0-beta.6
5.0.0-beta.7
5.0.0-beta.8
5.0.0-beta.9
6.*
6.0.0-alpha.0
6.0.0-alpha.2
7.*
7.0.0
7.0.0-alpha.0
7.0.0-beta.1
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.0-rc.2
7.1.0
7.1.0-rc.1
7.2.0-rc.1
7.2.1-WHPG
7.2.1-WHPG-rc.1
7.3.0-WHPG
7.4.0-WHPG
7.5.0-WHPG
Other
Pre-5-disk-layout-change
after-gpdb-import

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-96538.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "279691259162325795047155503270589209716",
                "94338822219973484603989971623128309677",
                "307207209534602546280089211810786674153",
                "281984945520123169601669934821703889191"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-96538-0115e86a",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/warehouse-pg/warehouse-pg/commit/0f73ef6e0729cbf71cf225b41d58e1bd1090f335",
        "target":  {
            "file":  "src/backend/commands/tablecmds.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "145924906675343794861975581163620471016",
            "length":  8887
        },
        "id":  "CVE-2026-96538-0ffb0a92",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/warehouse-pg/warehouse-pg/commit/0f73ef6e0729cbf71cf225b41d58e1bd1090f335",
        "target":  {
            "file":  "src/backend/commands/tablecmds.c",
            "function":  "ATExecCmd"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "337680920052192749058741100333826059",
                "296310647695340313245485398479492098519",
                "40525547950259603441937231036355526451"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-96538-303201dc",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/warehouse-pg/warehouse-pg/commit/0f73ef6e0729cbf71cf225b41d58e1bd1090f335",
        "target":  {
            "file":  "src/backend/access/common/reloptions_gp.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "107904805491728235191080553999062545204",
                "330881260831693395715623471542678691258",
                "152479651265714095047382295034711693471"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-96538-b0fb2ee0",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/warehouse-pg/warehouse-pg/commit/0f73ef6e0729cbf71cf225b41d58e1bd1090f335",
        "target":  {
            "file":  "src/include/access/reloptions.h"
        }
    }
]
vanir_signatures_modified
"2026-10-02T08:13:39Z"