Description
WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.
Published: 2026-09-28
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation leading to Arbitrary File Manipulation and potential Code Execution
Action: Immediate Patch
AI Analysis

Impact

WarehousePG versions 7.x prior to 7.6.0-WHPG allow any authenticated database role to invoke the server‑side file functions pg_file_write, pg_file_rename, pg_file_unlink, and pg_logdir_ls with no required GRANT, due to a missing REVOKE that the adminpack extension would normally apply. This missing authorization enables non‑superusers to create, modify, rename, and delete files under the data and log directories, including editing the postgresql.auto.conf file to insert configuration directives that culminate in arbitrary code execution at the next server restart or reload. The vulnerability is characterized by CWE‑862, which denotes an improper authorization flaw.

Affected Systems

The affected product is EnterpriseDB WarehousePG 7.x before the 7.6.0‑WHPG release. WarehousePG 6.x is not affected because the corresponding functions there perform an internal superuser check.

Risk and Exploitability

The CVSS base score of 8.7 indicates high severity, but the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. However, the vulnerability can be exploited by any authenticated role without special privileges, making the attack vector highly likely in environments where users have database access. The absence of a required GRANT means that an attacker need only have a valid database login to abuse the functions, and the impact can include persistence of malicious code through configuration changes.

Generated by OpenCVE AI on September 28, 2026 at 16:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WarehousePG to version 7.6.0-WHPG or later, which contains the proper authorization checks for the file functions
  • Revoke the EXECUTE privilege on pg_file_write, pg_file_rename, pg_file_unlink, and pg_logdir_ls from all non‑superuser roles after upgrading
  • Restrict write permissions on the data and log directories and ensure postgresql.auto.conf is read‑only for non‑superuser roles, and monitor for unauthorized modifications

Generated by OpenCVE AI on September 28, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum's merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.
Title WarehousePG pg_file_write/pg_file_rename/pg_file_unlink/pg_logdir_ls privilege escalation
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: EDB

Published:

Updated: 2026-09-28T16:22:25.908Z

Reserved: 2026-09-23T11:52:41.065Z

Link: CVE-2026-96538

cve-icon Vulnrichment

Updated: 2026-09-28T16:22:15.497Z

cve-icon NVD

Status : Received

Published: 2026-09-28T15:17:25.357

Modified: 2026-09-28T17:17:53.400

Link: CVE-2026-96538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T16:30:03Z

Weaknesses