Improper Task State Validation in Backstage Scaffolder Backend Plugin Affecting Developer Portals
CVE-2026-106500

8.5HIGH

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106500?

The @backstage/plugin-scaffolder-backend package, used in Backstage developer portals, suffers from an improper task state validation issue. This vulnerability allows authenticated users with permissions to create and access Scaffolder tasks to manipulate files that are accessible to the Backstage backend under certain timing and deployment circumstances. If the backend application files are writable, this may lead to compromises in the confidentiality, integrity, and availability of backend resources. Users are advised to upgrade to the patched versions 3.3.1, 3.4.1, 4.0.3, or 4.1.0 to mitigate this risk.

Affected Version(s)

backstage < 1.49.6 < 1.49.6

backstage >= 1.50.0-next.0, < 1.50.5 < 1.50.0-next.0, 1.50.5

backstage >= 1.51.0-next.0, < 1.54.6 < 1.51.0-next.0, 1.54.6

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.