Impact
WarehousePG versions 7.x prior to 7.6.0-WHPG allow any authenticated database role to invoke the server‑side file functions pg_file_write, pg_file_rename, pg_file_unlink, and pg_logdir_ls with no required GRANT, due to a missing REVOKE that the adminpack extension would normally apply. This missing authorization enables non‑superusers to create, modify, rename, and delete files under the data and log directories, including editing the postgresql.auto.conf file to insert configuration directives that culminate in arbitrary code execution at the next server restart or reload. The vulnerability is characterized by CWE‑862, which denotes an improper authorization flaw.
Affected Systems
The affected product is EnterpriseDB WarehousePG 7.x before the 7.6.0‑WHPG release. WarehousePG 6.x is not affected because the corresponding functions there perform an internal superuser check.
Risk and Exploitability
The CVSS base score of 8.7 indicates high severity, but the EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. However, the vulnerability can be exploited by any authenticated role without special privileges, making the attack vector highly likely in environments where users have database access. The absence of a required GRANT means that an attacker need only have a valid database login to abuse the functions, and the impact can include persistence of malicious code through configuration changes.
OpenCVE Enrichment