Inconsistent Credential Enforcement in Backstage Proxy Plugin
CVE-2026-106456
4.8MEDIUM
What is CVE-2026-106456?
The Backstage framework contains a vulnerability in the @backstage/plugin-proxy-backend package, impacting versions from 0.5.0 to 0.6.18. This flaw arises from inconsistent credential enforcement across overlapping proxy routes, allowing operators to set different credential requirements for parent and nested paths. When unauthenticated access is permitted on a parent path, it mistakenly allows unauthorized users to access nested routes that require credentials. Consequently, this may lead to unauthorized access to sensitive resources via static credentials associated with the proxy. The issue has been resolved in version 0.6.18.
Affected Version(s)
backstage >= 1.28.0, < 1.55.0
plugin-proxy-backend >= 0.5.0, < 0.6.18
