CVE-2026-106492

Summary

Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for. This issue is fixed in versions 0.16.1 and 0.17.8.

Affected Software

VendorProductVersion RangeStatus
backstagebackstage< 1.49.6affected
backstagebackstage>= 1.50.0-next.0, < 1.54.6affected
@backstagebackend-defaults< 0.16.1affected
@backstagebackend-defaults>= 0.17.0, < 0.17.8affected

Weaknesses

  • CWE-269: CWE-269: Improper Privilege Management
  • CWE-863: CWE-863: Incorrect Authorization

References