Inconsistent Credential Enforcement in Backstage Proxy Plugin
CVE-2026-106456

4.8MEDIUM

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106456?

The Backstage framework contains a vulnerability in the @backstage/plugin-proxy-backend package, impacting versions from 0.5.0 to 0.6.18. This flaw arises from inconsistent credential enforcement across overlapping proxy routes, allowing operators to set different credential requirements for parent and nested paths. When unauthenticated access is permitted on a parent path, it mistakenly allows unauthorized users to access nested routes that require credentials. Consequently, this may lead to unauthorized access to sensitive resources via static credentials associated with the proxy. The issue has been resolved in version 0.6.18.

Affected Version(s)

backstage >= 1.28.0, < 1.55.0

plugin-proxy-backend >= 0.5.0, < 0.6.18

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.