CVE-2026-106493

low

Description

Backstage is an open framework for building developer portals. Prior to 1.54.6, cloud storage catalog providers did not sufficiently validate object paths. A principal able to create or rename objects in a configured Azure Blob Storage or AWS S3 catalog source could cause catalog descriptors to be read from outside the intended storage boundary, limited to locations reachable with the backend's configured credentials. This issue is fixed in 1.54.6.

References

https://github.com/backstage/backstage/security/advisories/GHSA-xvh9-35w9-42m4

https://github.com/backstage/backstage/releases/tag/v1.54.6

https://github.com/backstage/backstage/commit/47ddbd8b4a3efd812309f759c38f4877fbd9e5ff

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-94013

Details

Source: Mitre, NVD

Published: 2026-10-06

Updated: 2026-10-07

Risk Information

CVSS v2

Base Score: 1.7

Vector: CVSS2#AV:N/AC:H/Au:M/C:P/I:N/A:N

Severity: Low

CVSS v3

Base Score: 3

Vector: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

Severity: Low

EPSS

EPSS: 0.00259