PULSE
FEED
ransomumbra reclama a Tharisa · ZA · Manufacturingransomn0n reclama a Chibitek · US · Technologyransomincransom reclama a acmestamping.com · US · Manufacturingransomincransom reclama a harborpacific.com · US · Transportationransomincransom reclama a architekt-vondanwitz.de · DE · Professional Servicesransomtermite reclama a Aon · US · Professional Servicesransomqilin reclama a EPTISA · ES · Professional Servicesransomsilentransomgroup reclama a Andersen Group · Professional Servicesransompanzer reclama a EDFelectronics · Manufacturingransomumbra reclama a Beni Suef Technological University – BTU · EG · Educationransomvexy ransomware reclama a KOOKABARRA JUICE · AU · Retail & E-Commerceransomqilin reclama a BNYH · Financial Servicesransomqilin reclama a Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi · TR · Manufacturingransompanzer reclama a SweetRush · US · Professional Servicesransomumbra reclama a Tharisa · ZA · Manufacturingransomn0n reclama a Chibitek · US · Technologyransomincransom reclama a acmestamping.com · US · Manufacturingransomincransom reclama a harborpacific.com · US · Transportationransomincransom reclama a architekt-vondanwitz.de · DE · Professional Servicesransomtermite reclama a Aon · US · Professional Servicesransomqilin reclama a EPTISA · ES · Professional Servicesransomsilentransomgroup reclama a Andersen Group · Professional Servicesransompanzer reclama a EDFelectronics · Manufacturingransomumbra reclama a Beni Suef Technological University – BTU · EG · Educationransomvexy ransomware reclama a KOOKABARRA JUICE · AU · Retail & E-Commerceransomqilin reclama a BNYH · Financial Servicesransomqilin reclama a Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi · TR · Manufacturingransompanzer reclama a SweetRush · US · Professional Services
← Todos los CVEs
CVE Watch6 oct 2026

CVE-2026-106496

Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by

CVSS

3.1

Bajo

EPSS

—

KEV

—

Exploit Today

0

0-100

Publicado: 6 oct 2026 · Última mod.: 6 oct 2026 · CWE-22 · CWE-863

EPSS · 30d

Sin historial EPSS suficiente todavía.

Descripción técnica

Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host. This issue is fixed in version 3.9.1.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1038705.0 MED
—
———A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service.9h
CVE-2026-81535—
—
———In wolfSSH through 1.5.0 built with --enable-fwd, DoChannelOpen() in src/internal.c gates only direct-tcpip channel opens with the forwarding policy callback. forwarded-tcpip opens are admitted without an authorization check and are not capped in number, allowing a malicious SSH peer to make an endpoint allocate unbounded per-channel buffers for forwarding channels the application never authorized. A client also does not check a forwarded-tcpip open against the forwards it registered with a tcpip-forward request, as RFC 4254 section 7.2 requires, so a malicious server can open forwarding channels for addresses and ports the client never asked it to forward.12h
CVE-2026-1064718.1 ALT
—
———A flaw was found in Candlepin. The central authorization filter incorrectly grants access when any one of multiple @Verify-annotated parameters is accessible, instead of requiring access to every verified entity. A low-privilege authenticated attacker who can access the first referenced object can bypass authorization checks on subsequent objects. When target resource identifiers are known, this can enable unauthorized disclosure of consumer information and unauthorized modification of entitlements and related subscription resources, including across organizations.13h
CVE-2026-976716.5 MED
—
——0IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.14h
CVE-2026-934486.5 MED
—
——0IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.14h
CVE-2026-1033608.1 ALT
—
——0IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.14h