Improper Authorization in Backstage TechDocs Plugin by Spotify
CVE-2026-106489
What is CVE-2026-106489?
Backstage, an open-source framework for building developer portals, has a vulnerability in the @backstage/plugin-techdocs-backend package. This issue allows an authenticated user with access to one TechDocs documentation site to manipulate URLs in such a way as to access documentation belonging to another entity. This security risk is particularly relevant for deployments that utilize an external TechDocs builder with external storage providers like S3 or GCS and have the permission framework activated. It is important to note that instances relying on the permission framework are vulnerable, while those that do not are unaffected by this issue. The vulnerability has been addressed and resolved in version 2.2.4.
Affected Version(s)
backstage < 1.54.6
plugin-techdocs-backend < 2.2.4
