Configuration Bypass in Backstage TechDocs Plugin by Backstage
CVE-2026-106556

7.7HIGH

Key Information:

Vendor

Backstage

Vendor
CVE Published:
7 October 2026

What is CVE-2026-106556?

The Backstage TechDocs plugin is vulnerable to a configuration bypass issue in the mkdocs.yml sanitization process. This vulnerability allows authenticated users with permissions to register or modify documentation sources to execute arbitrary commands within the TechDocs build environment. The insufficient validation of MkDocs configuration can lead to exploitation, affecting only resources accessible to the TechDocs backend or build container. It is crucial for users to upgrade to versions 1.14.6 or later to mitigate this risk.

Affected Version(s)

backstage < 1.50.5 < 1.50.5

backstage >= 1.51.0-next.0, < 1.54.6 < 1.51.0-next.0, 1.54.6

plugin-techdocs-node < 1.14.6 < 1.14.6

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.