---
id: CVE-2026-106493
title: Backstage is an open framework for building developer portals
summary: >-
  Backstage is an open framework for building developer portals. Prior to
  1.54.6, cloud storage catalog providers did not sufficiently validate object
  paths. A principal able to create or rename objects in a configured Azure Blob
  Storage o…
severity: low
cvss: 3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-22
vendor: backstage
product: backstage
affected:
  - backstage < 1.54.6
  - plugin-catalog-backend-module-azure < 0.17.8
  - plugin-catalog-backend-module-aws < 0.4.27
  - plugin-catalog-backend-module-azure < 0.3.21
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:18.370'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106493'
references:
  - url: >-
      https://github.com/backstage/backstage/commit/47ddbd8b4a3efd812309f759c38f4877fbd9e5ff
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.54.6'
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/security/advisories/GHSA-xvh9-35w9-42m4
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T21:20:28.985Z'
---

## Overview

Backstage is an open framework for building developer portals. Prior to 1.54.6, cloud storage catalog providers did not sufficiently validate object paths. A principal able to create or rename objects in a configured Azure Blob Storage or AWS S3 catalog source could cause catalog descriptors to be read from outside the intended storage boundary, limited to locations reachable with the backend's configured credentials. This issue is fixed in 1.54.6.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
