Credential Boundary Bypass in Backstage Framework
CVE-2026-106462

6.4MEDIUM

What is CVE-2026-106462?

The Backstage Framework, an open-source platform for developing developer portals, has a vulnerability where scaffolder source-control actions may not consistently enforce the intended credential boundaries. This can enable an authenticated user to unintentionally trigger operations with broader integration credentials, granting access privileges beyond what was intended. To mitigate this issue, users are advised to upgrade to version 1.54.6 and ensure that the 'scaffolder.requireScmUserCredentials' option is enabled.

Affected Version(s)

backstage < 1.54.6

plugin-scaffolder-backend < 4.1.0

plugin-scaffolder-backend-module-azure < 0.2.25

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.