PT-2026-107278 · Backstage · Backstage
CVE-2026-106493
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v3.1
3.0
Low
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Backstage versions prior to 1.54.6
Description
Cloud storage catalog providers do not sufficiently validate object paths. A principal with permissions to create or rename objects in a configured AWS S3 or Azure Blob Storage catalog source can cause catalog descriptors to be read from outside the intended storage boundary, restricted to locations accessible by the backend's configured credentials.
Recommendations
Update to version 1.54.6.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Backstage