Improper Input Validation in Backstage Plugin by Spotify
CVE-2026-106490

6.5MEDIUM

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106490?

The Backstage framework, particularly the @backstage/plugin-techdocs-backend package, is susceptible to improper input validation in static content requests. Users authorized within Backstage using the Azure Blob Storage provider may inadvertently gain access to restricted TechDocs content if entity-level permissions are engaged. This vulnerability is pronounced in deployments that have disabled the default backend authentication policy, leading to increased exposure risk. The issue has been resolved in version 2.2.4, encouraging prompt updates to mitigate potential threats.

Affected Version(s)

backstage < 1.54.6

plugin-techdocs-backend < 2.2.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.