Executive brief
PostgreSQL database backup and synchronization tools contain a flaw that allows a malicious database administrator to overwrite sensitive files on the system performing the backup. This could allow an attacker to gain full control over the underlying operating system account by modifying configuration files like .bashrc. The risk is highest when backup files are moved between systems or snapshotted before the database server is restarted.
Technical details
A symbolic link (symlink) following vulnerability exists in the PostgreSQL client tools pg_basebackup (when using plain format) and pg_rewind. A database superuser on the source (origin) server can craft malicious symlinks that cause these tools to overwrite arbitrary files on the local filesystem where the tools are being executed. This can lead to privilege escalation or account takeover by overwriting sensitive files such as .bashrc. The vulnerability is particularly relevant in scenarios where the backup files are manipulated (e.g., moved to a different VM or snapshotted) before the database server is started. Patches are available in PostgreSQL versions 18.4, 17.10, 16.14, 15.18, and 14.23.
Affected products
- PostgreSQL PostgreSQL < 18.4, < 17.10, < 16.14, < 15.18, < 14.23
Timeline
- 2026-05-12: patched: Fixes released for supported versions.
- 2026-05-14: disclosed: Public advisory published.