Path Traversal Issue in Backstage Cloud Storage Integration
CVE-2026-106493
3LOW
What is CVE-2026-106493?
Prior to version 1.54.6, Backstage, an open framework for building developer portals, was susceptible to a path traversal vulnerability. Specifically, the issue arose in cloud storage catalog providers which failed to adequately validate object paths. This flaw allowed a principal with permissions to create or rename objects in configured Azure Blob Storage or AWS S3 sources to potentially read catalog descriptors from unintended storage locations, within the reach of the backend's configured credentials. This vulnerability has been addressed in the subsequent release, enhancing the security of the system.
Affected Version(s)
backstage < 1.54.6
plugin-catalog-backend-module-aws < 0.4.27
plugin-catalog-backend-module-azure < 0.17.8
