« Back to list

CVE-2026-106458

Status: ReceivedMedium (6.5)—

Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository filtering in bitbucket server catalog event updates. Deployments using event-driven updates in the Bitbucket Server catalog provider may ingest catalog locations from repositories that are excluded by the provider's configured project, repository, or archived-repository filters.

Read full descriptionShow less

An authenticated Bitbucket Server user who can push to a filtered-out repository that remains readable by the configured Backstage integration can trigger a legitimate repository event. The affected event path may then add a Location for that repository even though scheduled discovery excludes it. This issue is fixed in version 0.5.15.

CVSS

Exploitation probability (EPSS)

FIRST hasn't scored this CVE yet (usual for very recent or rejected CVEs).

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Autenticado en Bitbucket Server (PR:L) puede manipular eventos para eludir filtros, accediendo a ubicaciones catalogadas indebidamente. Integridad alta (I:H) indica modificación de configuración/datos de catálogo.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-106458",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "backstage",
          "product": "backstage",
          "versions": [
            {
              "status": "affected",
              "version": ">= 1.38.0, < 1.55.0"
            }
          ]
        },
        {
          "vendor": "@backstage",
          "product": "plugin-catalog-backend-module-bitbucket-server",
          "versions": [
            {
              "status": "affected",
              "version": ">= 0.4.0, < 0.5.15"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-10-06T21:17:16.270",
  "references": [
    {
      "url": "https://github.com/backstage/backstage/commit/989db63b6f87c8fc04d440f296ad89e10c79b363",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/backstage/backstage/releases/tag/v1.55.0",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/backstage/backstage/security/advisories/GHSA-c36c-cf6r-ghgj",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Received",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository filtering in bitbucket server catalog event updates. Deployments using event-driven updates in the Bitbucket Server catalog provider may ingest catalog locations from repositories that are excluded by the provider's configured project, repository, or archived-repository filters. An authenticated Bitbucket Server user who can push to a filtered-out repository that remains readable by the configured Backstage integration can trigger a legitimate repository event. The affected event path may then add a Location for that repository even though scheduled discovery excludes it. This issue is fixed in version 0.5.15."
    }
  ],
  "lastModified": "2026-10-06T21:17:16.270",
  "sourceIdentifier": "security-advisories@github.com"
}