CVE tracker
393 subscribers
5.79K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-101149 - Security Advisory 0186

CVE ID :CVE-2026-101149
Published : Oct. 6, 2026, 7:37 p.m. | 11 minutes ago
Description :Insufficient validation of OIDC SSO provider configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101150 - Security Advisory 0186

CVE ID :CVE-2026-101150
Published : Oct. 6, 2026, 7:37 p.m. | 11 minutes ago
Description :Insufficient validation of OIDC bearer token configuration could allow a user with specific high privileges to direct requests to arbitrary destinations.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101151 - Security Advisory 0187

CVE ID :CVE-2026-101151
Published : Oct. 6, 2026, 7:37 p.m. | 11 minutes ago
Description :Insufficient validation of request in login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, redirects the user's browser to an arbitrary external site upon completion of the authentication process.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101152 - Security Advisory 0187

CVE ID :CVE-2026-101152
Published : Oct. 6, 2026, 7:37 p.m. | 11 minutes ago
Description :Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
Severity: 8.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-101153 - Security Advisory 0188

CVE ID :CVE-2026-101153
Published : Oct. 6, 2026, 7:38 p.m. | 11 minutes ago
Description :On affected versions of CloudVision Portal (on-premises) or CloudVision Sensor, a path traversal vulnerability exists. An authenticated user with sufficient high privileges could exploit this to extract unintended data from the Sensor.
Severity: 8.0 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106497 - Backstage: Inconsistent catalog property permission evaluation

CVE ID :CVE-2026-106497
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated user could receive catalog entity data that policy authors intended to restrict. This issue is fixed in version 3.9.1.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106498 - Backstage: Improper URL validation in catalog entity placeholder resolution

CVE ID :CVE-2026-106498
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity's source repository. Under certain configurations, this could allow access to data not intended to be available to the user. This issue is fixed in versions 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106499 - Backstage: Secret-derived values may be exposed in scaffolder task logs

CVE ID :CVE-2026-106499
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose secret-derived values in Scaffolder task logs. Deployments that configure sensitive scaffolder.defaultEnvironment.secrets and allow an attacker to create or modify Scaffolder templates are affected. A template author could cause secret-derived values used during template iteration to be persisted and exposed to users who can access the resulting task logs. This issue is fixed in version 4.1.0.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106500 - Backstage: Improper task state validation in Scaffolder backend

CVE ID :CVE-2026-106500
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper task state validation in scaffolder backend. An authenticated user with permission to create and access Scaffolder tasks may, under specific timing and deployment conditions, affect files accessible to the Backstage backend. If backend application files are writable, the confidentiality, integrity, and availability of the backend may be compromised. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106501 - Backstage: Sensitive information exposure in Scaffolder

CVE ID :CVE-2026-106501
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data. In deployments where that data contains credentials for an external service, this may permit disclosure and unauthorized changes in that external service. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.
Severity: 9.6 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106502 - Backstage: Sensitive information may be exposed in Scaffolder task failure events

CVE ID :CVE-2026-106502
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package could expose sensitive information in Scaffolder task failure events. Under specific template and failure conditions, an authenticated user may retrieve backend-managed credentials used during task execution from affected task events. This issue is fixed in version 4.1.0.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106503 - Backstage: Scaffolder action input authorization bypass

CVE ID :CVE-2026-106503
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authorization bypass. An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106504 - Backstage: Sensitive information exposure in scaffolder task logs

CVE ID :CVE-2026-106504
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder task logs. An authenticated user who can create and read scaffolder tasks may be able to observe sensitive values in task logs in deployments with restrictive action permissions and affected templates. Exploitation requires a denied action whose input contains such a value. This issue is fixed in version 4.1.0.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106505 - Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend

CVE ID :CVE-2026-106505
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package is affected by bypass of mkdocs configuration sanitizer in techdocs backend. Users with the ability to commit changes to a repository that uses TechDocs can circumvent the MkDocs configuration file sanitizer introduced in response to CVE-2026-25153 and execute arbitrary code on the TechDocs backend host during documentation generation. This issue is fixed in versions 1.14.6 and 1.15.4.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106506 - Backstage: Improper input validation in scaffolder task list ordering

CVE ID :CVE-2026-106506
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106507 - Backstage: TechDocs arbitrary file read via mkdocs snippets

CVE ID :CVE-2026-106507
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by techdocs arbitrary file read via mkdocs snippets. Unsafe path resolution in TechDocs source tree handling allows an authenticated user who can register documentation sources to include content from outside the intended documentation boundary. Depending on deployment, this may expose files readable by the build process. This issue is fixed in version 1.15.4.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106508 - Backstage: Potential file exposure through local TechDocs publisher

CVE ID :CVE-2026-106508
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 1.15.4, the @backstage/plugin-techdocs-node package is affected by potential file exposure through local techdocs publisher. When using the local TechDocs publisher (techdocs.publisher.type: 'local'), it was possible for the documentation serving endpoint to follow filesystem references outside the intended documentation tree, potentially exposing host files to authenticated users. This is mitigated by the fact that exploration requires preconditions that do not arise through normal MkDocs operation. Cloud-based publishers (S3, GCS, Azure Blob Storage) are not affected. This issue is fixed in version 1.15.4.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106509 - Backstage: Improper validation of MkDocs theme configuration in TechDocs

CVE ID :CVE-2026-106509
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to build documentation locally or in a container, a user with write access to a registered repository can include configuration values in mkdocs.yml that cause arbitrary code execution during the documentation build process. This issue is fixed in versions 1.14.6 and 1.15.4.
Severity: 7.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106587 - OpenSSH sshd Configuration Option Misinterpretation Vulnerability

CVE ID :CVE-2026-106587
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 33 minutes ago
Description :In sshd in OpenSSH before 10.6, the value "none" for a configuration option is sometimes interpreted as a filename but was intended to mean that a feature is disabled.
Severity: 3.6 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106588 - OpenSSH sshd Sandbox Bypass

CVE ID :CVE-2026-106588
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 32 minutes ago
Description :In sshd in OpenSSH through 10.6, use of the macOS 27 (or later) SDK has the side effect of loss of sandboxing, which is potentially unexpected.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-106589 - OpenSSH sshd Privilege Escalation

CVE ID :CVE-2026-106589
Published : Oct. 6, 2026, 10:17 p.m. | 1 hour, 32 minutes ago
Description :In sshd in OpenSSH through 10.6, in certain environments such as QNX 6 and SCO OpenServer 5, sshd-session can unexpectedly have root privileges. This is related to the GatewayPorts and StreamLocalForwarding configuration options, and lack of support for file-descriptor passing and unprivileged allocation of PTY devices.
Severity: 2.9 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...