Access Mismanagement in Backstage Framework from Vendor Backstage
CVE-2026-106492
What is CVE-2026-106492?
The Backstage framework exhibits an access control vulnerability due to improper handling of service credential delegation. Prior to versions 0.16.1 and 0.17.8, the @backstage/backend-defaults package did not enforce access restrictions effectively. This flaw allows an external service with limited access (e.g., read-only) to bypass those restrictions by exploiting the plugin delegation paths. Consequently, a compromised service could execute write operations, violating its designated permissions and potentially affecting the integrity and security of the applications using the framework. Upgrading to the latest versions is essential to mitigate this risk.
Affected Version(s)
backend-defaults < 0.16.1 < 0.16.1
backend-defaults >= 0.17.0, < 0.17.8 < 0.17.0, 0.17.8
backstage < 1.49.6 < 1.49.6
