Description
Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and passes them to the cloud provider's delete API using Barman's own credentials, without verifying that the snapshots belong to that backup. An attacker who can overwrite backup.info but lacks snapshot delete permissions can substitute the identifiers of other snapshots, causing Barman to delete any snapshot its cloud identity can reach on AWS, Microsoft Azure, or Google Cloud. Exploitation requires a deployment where the principal that writes the backup catalog is separate from the identity Barman uses to delete snapshots. Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue is fixed in Barman 3.20.1.
Published: 2026-09-29
Score: 7.2 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade to Barman 3.20.1 or later. Before deleting a snapshot, Barman now reads the snapshot name from the cloud provider and refuses the deletion unless it matches the backup being deleted.


Vendor Workaround

Restrict write access to the backup catalog in object storage to the identity Barman uses. Enable object versioning or object lock on the backup bucket, and on AWS use EBS Snapshot Lock (aws_snapshot_lock_mode) to protect snapshots from deletion.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and passes them to the cloud provider's delete API using Barman's own credentials, without verifying that the snapshots belong to that backup. An attacker who can overwrite backup.info but lacks snapshot delete permissions can substitute the identifiers of other snapshots, causing Barman to delete any snapshot its cloud identity can reach on AWS, Microsoft Azure, or Google Cloud. Exploitation requires a deployment where the principal that writes the backup catalog is separate from the identity Barman uses to delete snapshots. Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue is fixed in Barman 3.20.1.
Title Barman snapshot backup deletion trusts unverified backup catalog metadata
Weaknesses CWE-283
References
Metrics cvssV4_0

{'score': 7.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: EDB

Published:

Updated: 2026-09-29T20:55:51.959Z

Reserved: 2026-09-18T18:52:15.463Z

Link: CVE-2026-93853

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T21:19:39.140

Modified: 2026-09-29T21:19:39.140

Link: CVE-2026-93853

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses