Inconsistent Location Type Enforcement in Backstage Plugin by Spotify
CVE-2026-106496

3.1LOW

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106496?

The @backstage/plugin-catalog-backend component of the Backstage framework by Spotify is susceptible to a vulnerability due to improper enforcement of permitted location types during catalog processing. This flaw allows for the processing of unauthorized location types under certain configurations, which can result in unintended file access on the backend host. Users are urged to upgrade to version 3.9.1 or later to mitigate this issue and enhance security.

Affected Version(s)

backstage < 1.54.6

plugin-catalog-backend < 3.9.1

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.