天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-93853 Barman 快照备份删除越权漏洞

影响攻击者可借 Barman 凭证删除任意云快照

AI 研判

Barman 在处理快照备份删除时,未校验 backup.info 中记录的快照标识是否真正属于该备份,直接使用自身云凭证调用云厂商删除接口。能够改写备份目录的攻击者可替换快照标识,导致 Barman 删除其云身份可访问的无关快照。该问题影响 AWS、Azure 与 Google Cloud 上的快照备份场景。

影响范围

Barman

Barman 3.4.0(Google Cloud)、3.6.0(Azure)、3.7.0(AWS)起至 3.20.0(含)受影响,3.20.1 已修复。

漏洞详情

漏洞属于越权/未验证所有权类问题。成因是删除快照时仅从 backup.info 读取快照 ID 并直接传给云厂商删除 API,未确认这些快照归属于当前备份。利用方式是攻击者先覆盖 backup.info,写入其他快照的标识,再触发显式删除或保留策略执行,从而借 Barman 的云凭证删除任意可达快照。

利用条件与风险

利用前提是写入备份目录的主体与 Barman 删除快照所用的云身份相互分离,且攻击者本身没有快照删除权限。实战中可造成云上快照被批量误删,影响数据恢复能力。

修复建议

升级至 Barman 3.20.1 或更高版本。临时缓解措施包括限制对备份目录及 backup.info 的写入权限,并遵循最小权限原则收紧 Barman 云身份的快照删除范围。

原始情报

Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and passes them to the cloud provider’s delete API using Barman’s own credentials, without verifying that the snapshots belong to that backup. An attacker who can overwrite backup.info but lacks snapshot delete permissions can substitute the identifiers of other snapshots, causing Barman to delete any snapshot its cloud identity can reach on AWS, Microsoft Azure, or Google Cloud. Exploitation requires a deployment where the principal that writes the backup catalog is separate from the identity Barman uses to delete snapshots. Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue is fixed in Barman 3.20.1.