Email Verification Bypass in Backstage Plugin Auth Node by Spotify
CVE-2026-106460
What is CVE-2026-106460?
The Backstage plugin-auth-node by Spotify has a vulnerability where it fails to consistently enforce explicit negative email verification during the OAuth profile normalization process. This flaw allows a user, who is already authenticated through an identity provider, to submit or alter an unverified email. If the selected profile email is used to resolve catalog identities, the user may assume different identities and gain unauthorized access to associated permissions. This vulnerability affects Backstage versions ranging from 0.3.0 to 0.6.15 and 0.7.5, and it has been addressed in subsequent releases.
Affected Version(s)
backstage >= 1.18.0, < 1.49.7 < 1.18.0, 1.49.7
backstage >= 1.50.0-next.0, < 1.54.7 < 1.50.0-next.0, 1.54.7
plugin-auth-node >= 0.3.0, < 0.6.15 < 0.3.0, 0.6.15
