CVE-2026-96538 WarehousePG 缺失授权漏洞
影响普通数据库用户可写配置文件,最终以 postgres 用户身份执行任意代码
WarehousePG(WHPG)7.x 在 7.6.0-WHPG 之前存在缺失授权校验漏洞(CWE-862)。其内置服务端文件函数 pg_file_write、pg_file_rename、pg_file_unlink、pg_logdir_ls 未做权限限制,任意已认证数据库角色均可直接调用。攻击者可借此写入 postgresql.auto.conf,在服务重启或配置重载时实现任意代码执行。
影响范围
WarehousePG(WHPG)7.x 至 7.6.0-WHPG 之前的版本受影响;6.x 因相关函数仍保留权限校验而不受影响。
漏洞详情
漏洞源于 Greenplum 合并到 PostgreSQL 12 基座时,adminpack 原本对这些函数施加的 REVOKE 权限回收未同步到 WHPG 核心实现,导致函数目录项指向无权限门控的版本。任何已认证的非超级用户角色无需 GRANT 即可调用这些函数,在数据目录和日志目录下创建、覆盖(追加)、重命名、删除文件,并可用 pg_logdir_ls() 枚举日志文件名。由于 postgresql.auto.conf 位于数据目录,攻击者可向其追加 shared_preload_libraries、archive_command 等配置指令,从而在下次重启或配置重载时以 postgres 操作系统用户身份执行任意代码。
利用条件与风险
利用前提是攻击者拥有一个可登录的数据库账号(无需超级用户权限),实战中一旦获得低权限数据库凭据即可提权至操作系统层面,风险很高。
修复建议
官方修复方案为升级至 7.6.0-WHPG 或更高版本;临时缓解措施可考虑撤销相关函数对普通角色的执行权限或限制数据库账号访问,具体以官方公告为准。
WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and pg_logdir_ls(). These functions are executable by any authenticated database role with no GRANT required, because the REVOKE that contrib/adminpack applies to the equivalent functions was never carried over to WHPG core when their catalog entries were repointed to the ungated adminpack-derived implementations as part of Greenplum’s merge to a PostgreSQL 12 base. A non-superuser can use pg_file_write, pg_file_rename, and pg_file_unlink to create, overwrite (append), rename, and delete files under the data and log directories, and can use pg_logdir_ls() to enumerate log file names. Because postgresql.auto.conf resides in the data directory, a non-superuser can append configuration directives such as shared_preload_libraries or archive_command to it, resulting in arbitrary code execution as the postgres operating system user on the next server restart or configuration reload. WarehousePG 6.x is not affected, as the equivalent functions there enforce a superuser check internally.