{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-106486/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-106486"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["plugin-scaffolder-backend-module-bitbucket-cloud (\u003c 0.3.10)","plugin-scaffolder-backend-module-bitbucket-server (\u003c 0.2.25)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","backstage","vulnerability","cve-2026-106486"],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eThe Backstage Scaffolder backend modules for Bitbucket Cloud and Bitbucket Server contain an improper filesystem validation vulnerability, tracked as CVE-2026-106486. This flaw exists within the scaffolder actions responsible for interacting with Bitbucket repositories. An authenticated user who has the privileges to execute templates and the ability to influence the targeted Bitbucket repository parameter can supply malicious input to traverse the filesystem on the backend host. By manipulating these inputs, an attacker may escape the expected working directory, potentially reading sensitive configuration files, modifying application code, or deleting arbitrary files. This vulnerability poses a significant risk to backend integrity and confidentiality, particularly in environments where untrusted users have template creation or execution access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to perform unauthorized file operations on the host running the Backstage backend. This can result in the compromise of backend confidentiality (sensitive file exfiltration), integrity (malicious code injection), or availability (system file deletion). The scope of impact is limited by the permissions of the process running the Backstage backend service.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@backstage/plugin-scaffolder-backend-module-bitbucket-cloud\u003c/code\u003e to version 0.3.10 or later.\u003c/li\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@backstage/plugin-scaffolder-backend-module-bitbucket-server\u003c/code\u003e to version 0.2.25 or later.\u003c/li\u003e\n\u003cli\u003eApply administrative restrictions on Scaffolder template execution, limiting them to trusted users only.\u003c/li\u003e\n\u003cli\u003eAudit existing Scaffolder templates to identify and restrict actions that accept user-controlled target repository inputs until patching is complete.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:54:58Z","date_published":"2026-10-07T22:54:58Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-path-traversal/","summary":"Authenticated users can exploit improper filesystem validation in Backstage Bitbucket scaffolder plugins to achieve unauthorized file access, modification, or deletion outside the intended working directory via CVE-2026-106486.","title":"Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Modules","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-106486","version":"https://jsonfeed.org/version/1.1"}