PULSE
FEED
ransomumbra reclama a SANAtech Global Solutions · Technologyransomumbra reclama a Raqib · Technologyransomumbra reclama a Tharisa · ZA · Manufacturingransomn0n reclama a Chibitek · US · Technologyransomincransom reclama a acmestamping.com · US · Manufacturingransomincransom reclama a harborpacific.com · US · Transportationransomincransom reclama a architekt-vondanwitz.de · DE · Professional Servicesransomtermite reclama a Aon · US · Professional Servicesransomqilin reclama a EPTISA · ES · Professional Servicesransomsilentransomgroup reclama a Andersen Group · Professional Servicesransompanzer reclama a EDFelectronics · Manufacturingransomumbra reclama a Beni Suef Technological University – BTU · EG · Educationransomvexy ransomware reclama a KOOKABARRA JUICE · AU · Retail & E-Commerceransomqilin reclama a BNYH · Financial Servicesransomumbra reclama a SANAtech Global Solutions · Technologyransomumbra reclama a Raqib · Technologyransomumbra reclama a Tharisa · ZA · Manufacturingransomn0n reclama a Chibitek · US · Technologyransomincransom reclama a acmestamping.com · US · Manufacturingransomincransom reclama a harborpacific.com · US · Transportationransomincransom reclama a architekt-vondanwitz.de · DE · Professional Servicesransomtermite reclama a Aon · US · Professional Servicesransomqilin reclama a EPTISA · ES · Professional Servicesransomsilentransomgroup reclama a Andersen Group · Professional Servicesransompanzer reclama a EDFelectronics · Manufacturingransomumbra reclama a Beni Suef Technological University – BTU · EG · Educationransomvexy ransomware reclama a KOOKABARRA JUICE · AU · Retail & E-Commerceransomqilin reclama a BNYH · Financial Services
← Todos los CVEs
CVE Watch6 oct 2026

CVE-2026-106486

Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-clou

CVSS

8.5

Alto

EPSS

—

KEV

—

Exploit Today

0

0-100

Publicado: 6 oct 2026 · Última mod.: 6 oct 2026 · CWE-22 · CWE-59

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not sufficiently validate filesystem paths. An authenticated user who can execute an eligible template and influence an allowed Bitbucket repository could affect paths outside the expected working area, potentially compromising backend confidentiality, integrity, or availability. This issue is fixed in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud 0.3.10 and @backstage/plugin-scaffolder-backend-module-bitbucket-server 0.2.25.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1038705.0 MED
—
———A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service.11h
CVE-2026-976716.5 MED
—
——0IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.16h
CVE-2026-934486.5 MED
—
——0IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.16h
CVE-2026-1033608.1 ALT
—
——0IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.16h
CVE-2026-1065085.3 MED
—
——0Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving endpoint to follow filesystem references outside the intended documentation tree, potentially exposing host files to authenticated users. This is mitigated by the fact that exploration requires preconditions that do not arise through normal MkDocs operation. Cloud-based publishers (S3, GCS, Azure Blob Storage) are not affected. This issue is fixed in version 1.15.4.19h
CVE-2026-1065075.3 MED
—
——0Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary. Depending on deployment, this may expose files readable by the build process. This issue is fixed in version 1.15.4.19h