Email Verification Bypass in Backstage Plugin Auth Node by Spotify
CVE-2026-106460

6.8MEDIUM

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106460?

The Backstage plugin-auth-node by Spotify has a vulnerability where it fails to consistently enforce explicit negative email verification during the OAuth profile normalization process. This flaw allows a user, who is already authenticated through an identity provider, to submit or alter an unverified email. If the selected profile email is used to resolve catalog identities, the user may assume different identities and gain unauthorized access to associated permissions. This vulnerability affects Backstage versions ranging from 0.3.0 to 0.6.15 and 0.7.5, and it has been addressed in subsequent releases.

Affected Version(s)

backstage >= 1.18.0, < 1.49.7 < 1.18.0, 1.49.7

backstage >= 1.50.0-next.0, < 1.54.7 < 1.50.0-next.0, 1.54.7

plugin-auth-node >= 0.3.0, < 0.6.15 < 0.3.0, 0.6.15

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.