Insufficient Audience Validation in Backstage Auth Provider
CVE-2026-106457

6.8MEDIUM

What is CVE-2026-106457?

The @backstage/plugin-auth-backend-module-cloudflare-access-provider package in Backstage is vulnerable to insufficient audience validation. Versions from 0.1.0 to 0.5.0 fail to ensure that issued tokens for other applications are not accepted, potentially allowing unauthorized access to Backstage if valid tokens are inadvertently used. This oversight occurs due to the lack of verification that tokens are specifically assigned to the Backstage application, thus compromising the expected security model in a Cloudflare Zero Trust environment. The vulnerability has been addressed in version 0.5.0.

Affected Version(s)

backstage >= 1.26.0, < 1.55.0

plugin-auth-backend-module-cloudflare-access-provider >= 0.1.0, < 0.5.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.