Path Traversal Issue in Backstage Cloud Storage Integration
CVE-2026-106493

3LOW

What is CVE-2026-106493?

Prior to version 1.54.6, Backstage, an open framework for building developer portals, was susceptible to a path traversal vulnerability. Specifically, the issue arose in cloud storage catalog providers which failed to adequately validate object paths. This flaw allowed a principal with permissions to create or rename objects in configured Azure Blob Storage or AWS S3 sources to potentially read catalog descriptors from unintended storage locations, within the reach of the backend's configured credentials. This vulnerability has been addressed in the subsequent release, enhancing the security of the system.

Affected Version(s)

backstage < 1.54.6

plugin-catalog-backend-module-aws < 0.4.27

plugin-catalog-backend-module-azure < 0.17.8

References

CVSS V3.1

Score:
3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.