CVE-2026-106496
Description
A flaw was found in the Backstage plugin-catalog-backend component. Due to inconsistent enforcement of allowed location types during catalog processing, an authenticated remote attacker can submit location targets that should be restricted under specific configurations. This flaw can enable the backend service to process unauthorized locations, potentially leading to unintended file access on the host system.
Statement
This vulnerability is rated as Low severity for Red Hat products because triggering the flaw requires an authenticated user with permissions to submit catalog locations, alongside specific configuration prerequisites. Under standard deployments of Red Hat Developer Hub and Ansible Automation Platform, location ingestion rules and catalog sources are centrally administered, substantially limiting the blast radius. As a result, the risk of unauthorized local file retrieval through catalog entity processing remains low.
Mitigation
To mitigate this restrict catalog processing boundaries by confining the application's filesystem access to intended directories only and strictly audit your configuration to remove any overly permissive or untrusted location types.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 3.1 | N/A | 3.1 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | High | N/A | High |
| Privileges Required | Low | N/A | Low |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | Low | N/A | Low |
| Availability Impact | None | N/A | None |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
cve.org: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Understanding the Weakness (CWE)
Confidentiality,Integrity
Technical Impact: Read Files or Directories; Modify Files or Directories
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.