CVE-2026-106458
Last modified
CVE-2026-106458 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository filtering in bitbucket server catalog event updates. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository filtering in bitbucket server catalog event updates. Deployments using event-driven updates in the Bitbucket Server catalog provider may ingest catalog locations from repositories that are excluded by the provider's configured project, repository, or archived-repository filters. An authenticated Bitbucket Server user who can push to a filtered-out repository that remains readable by the configured Backstage integration can trigger a legitimate repository event. The affected event path may then add a Location for that repository even though scheduled discovery excludes it. This issue is fixed in version 0.5.15.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| backstage | backstage | >= 1.38.0, < 1.55.0 |
| @backstage | plugin-catalog-backend-module-bitbucket-server | >= 0.4.0, < 0.5.15 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-106458?
How severe is CVE-2026-106458?
How do I fix CVE-2026-106458?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-106452yawkat LZ4 Java provides LZ4 compression for Java. Prior to …5.3
- CVE-2026-106453yawkat LZ4 Java provides LZ4 compression for Java. Prior to …5.3
- CVE-2026-106454Twisted is an event-based framework for internet application…4.3
- CVE-2026-106455Backstage is an open framework for building developer portal…7.7
- CVE-2026-106456Backstage is an open framework for building developer portal…4.8
- CVE-2026-106457Backstage is an open framework for building developer portal…6.8
- CVE-2026-106459Backstage is an open framework for building developer portal…8.5
- CVE-2026-10646Zephyr's BSD-sockets getaddrinfo() implementation (subsys/ne…7.4
- CVE-2026-106460Backstage is an open framework for building developer portal…6.8
- CVE-2026-106461Backstage is an open framework for building developer portal…4.3
- CVE-2026-106462Backstage is an open framework for building developer portal…6.4
- CVE-2026-106463Backstage is an open framework for building developer portal…5.4
Are you affected by CVE-2026-106458?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
