Access Mismanagement in Backstage Framework from Vendor Backstage
CVE-2026-106492

7.6HIGH

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106492?

The Backstage framework exhibits an access control vulnerability due to improper handling of service credential delegation. Prior to versions 0.16.1 and 0.17.8, the @backstage/backend-defaults package did not enforce access restrictions effectively. This flaw allows an external service with limited access (e.g., read-only) to bypass those restrictions by exploiting the plugin delegation paths. Consequently, a compromised service could execute write operations, violating its designated permissions and potentially affecting the integrity and security of the applications using the framework. Upgrading to the latest versions is essential to mitigate this risk.

Affected Version(s)

backend-defaults < 0.16.1 < 0.16.1

backend-defaults >= 0.17.0, < 0.17.8 < 0.17.0, 0.17.8

backstage < 1.49.6 < 1.49.6

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.