Sensitive Information Exposure in Backstage Plugin from Backstage
CVE-2026-106504

6.5MEDIUM

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106504?

The @backstage/plugin-scaffolder-backend package in Backstage allows authenticated users to create and read scaffolder tasks. However, prior to version 4.1.0, this package is susceptible to sensitive information exposure via task logs. In environments with restrictive action permissions, a user may inadvertently observe sensitive values if the input to a denied action includes such data. This vulnerability necessitates careful management of permissions and input values to prevent unauthorized information disclosure.

Affected Version(s)

backstage < 1.54.6

plugin-scaffolder-backend < 4.1.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.