Insufficient Audience Validation in Backstage Auth Provider
CVE-2026-106457
6.8MEDIUM
What is CVE-2026-106457?
The @backstage/plugin-auth-backend-module-cloudflare-access-provider package in Backstage is vulnerable to insufficient audience validation. Versions from 0.1.0 to 0.5.0 fail to ensure that issued tokens for other applications are not accepted, potentially allowing unauthorized access to Backstage if valid tokens are inadvertently used. This oversight occurs due to the lack of verification that tokens are specifically assigned to the Backstage application, thus compromising the expected security model in a Cloudflare Zero Trust environment. The vulnerability has been addressed in version 0.5.0.
Affected Version(s)
backstage >= 1.26.0, < 1.55.0
plugin-auth-backend-module-cloudflare-access-provider >= 0.1.0, < 0.5.0
