enterprisedb has 3 CVEs on record between 2025 and 2026. 2 were published in the last 90 days. The median CVSS is 7.2 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Worst active — by depth score
CVE-2026-96538High· 8.7WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and p…48CVE-2026-93853High· 7.2Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots40CVE-2025-14038High· 7.0EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints39
enterprisedb vulnerabilities
CVEs affecting enterprisedb, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-93853High· 7.2Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots
Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy …
CVE-2026-96538High· 8.7WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and p…
WarehousePG (WHPG) 7.x before 7.6.0-WHPG is affected by a missing authorization vulnerability (CWE-862) in the built-in server-side file functions pg_file_write(text,text,bool), pg_file_rename(text,text,text), pg_file_unlink(text), and p…
CVE-2025-14038High· 7.0EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints
EDB Hybrid Manager contains a flaw that allows an unauthenticated attacker to directly access certain gRPC endpoints. This could allow an attacker to read potentially sensitive data or possibly cause a denial-of-service by writing malfor…