Back to database
Schedule35Medium6.4VulnerabilityCVE-2026-106462No patch link observed

CVE-2026-106462 — Backstage is an open framework for building developer portals.

Published Oct 6, 2026, 09:17 PM UTCIngested 2d agoSource NVD(cve-db)CVE-2026-106462

Description

Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user could cause an affected action to fall back to broader integration credentials and perform operations with more access than intended. This issue is fixed in 1.54.6 when operators also enable scaffolder.requireScmUserCredentials after upgrading.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
6.4

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

Low

Privileges Required

UI

None

User Interaction

S

Changed

Scope

C

Low

Confidentiality

I

Low

Integrity

A

None

Availability

Affected

Vendor
npm
Product
@backstage/plugin-scaffolder-backend

Versions

  • pkg:npm/%40backstage/plugin-scaffolder-backend < 4.1.0
  • pkg:npm/%40backstage/plugin-scaffolder-backend-module-github < 0.9.13
  • pkg:npm/%40backstage/plugin-scaffolder-backend-module-gitlab < 0.11.10
  • pkg:npm/%40backstage/plugin-scaffolder-backend-module-azure < 0.2.25
  • pkg:npm/%40backstage/plugin-scaffolder-backend-module-bitbucket-cloud < 0.3.10
  • pkg:npm/%40backstage/plugin-scaffolder-backend-module-bitbucket-server < 0.2.25

Stated as the source expressed them.