Tag
high
advisory
Improper Authentication Vulnerability in Backstage OIDC Provider
1 TTP 1 CVEA vulnerability in the Backstage OIDC authentication module allows authenticated users to spoof identities when using email-based resolution with unverified email providers, leading to unauthorized access.
plugin-auth-backend-module-oidc-provider
authentication-bypass
cve-2026-106488
backstage
1t
1c
high
advisory
Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Modules
1 TTP 1 CVEAuthenticated users can exploit improper filesystem validation in Backstage Bitbucket scaffolder plugins to achieve unauthorized file access, modification, or deletion outside the intended working directory via CVE-2026-106486.
plugin-scaffolder-backend-module-bitbucket-cloud +1
path-traversal
backstage
vulnerability
cve-2026-106486
1t
1c
critical
advisory
Sensitive Information Exposure in Backstage Scaffolder Plugin
2 TTPs 1 CVEAn authenticated user can access internal task execution data in Backstage, potentially exposing credentials stored within Scaffolder tasks to unauthorized parties.
plugin-scaffolder-backend +2
vulnerability
cloud-native
backstage
cve
rce
privilege-escalation
2t
1c