Improper Input Validation in Backstage Plugin by Spotify
CVE-2026-106490
6.5MEDIUM
What is CVE-2026-106490?
The Backstage framework, particularly the @backstage/plugin-techdocs-backend package, is susceptible to improper input validation in static content requests. Users authorized within Backstage using the Azure Blob Storage provider may inadvertently gain access to restricted TechDocs content if entity-level permissions are engaged. This vulnerability is pronounced in deployments that have disabled the default backend authentication policy, leading to increased exposure risk. The issue has been resolved in version 2.2.4, encouraging prompt updates to mitigate potential threats.
Affected Version(s)
backstage < 1.54.6
plugin-techdocs-backend < 2.2.4
