Credential Boundary Bypass in Backstage Framework
CVE-2026-106462
6.4MEDIUM
What is CVE-2026-106462?
The Backstage Framework, an open-source platform for developing developer portals, has a vulnerability where scaffolder source-control actions may not consistently enforce the intended credential boundaries. This can enable an authenticated user to unintentionally trigger operations with broader integration credentials, granting access privileges beyond what was intended. To mitigate this issue, users are advised to upgrade to version 1.54.6 and ensure that the 'scaffolder.requireScmUserCredentials' option is enabled.
Affected Version(s)
backstage < 1.54.6
plugin-scaffolder-backend < 4.1.0
plugin-scaffolder-backend-module-azure < 0.2.25
