Sensitive Information Exposure in Backstage Plugin by Backstage
CVE-2026-106502

5.3MEDIUM

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106502?

The @backstage/plugin-scaffolder-backend is susceptible to a vulnerability that may expose sensitive backend-managed credentials during task execution failures. Specifically, under certain template configurations and failure scenarios, authenticated users could access sensitive data from task failure events. This issue highlights the importance of ensuring proper access controls and integrity measures, and has been addressed in version 4.1.0 of the plugin. For more detailed information, please refer to the official advisory.

Affected Version(s)

backstage < 1.54.6

plugin-scaffolder-backend < 4.1.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.