CVE-2026-106462 — Backstage is an open framework for building developer portals.
Description
Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user could cause an affected action to fall back to broader integration credentials and perform operations with more access than intended. This issue is fixed in 1.54.6 when operators also enable scaffolder.requireScmUserCredentials after upgrading.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
Low
Privileges Required
UI
None
User Interaction
S
Changed
Scope
C
Low
Confidentiality
I
Low
Integrity
A
None
Availability
Affected
- Vendor
- npm
- Product
- @backstage/plugin-scaffolder-backend
Versions
- pkg:npm/%40backstage/plugin-scaffolder-backend < 4.1.0
- pkg:npm/%40backstage/plugin-scaffolder-backend-module-github < 0.9.13
- pkg:npm/%40backstage/plugin-scaffolder-backend-module-gitlab < 0.11.10
- pkg:npm/%40backstage/plugin-scaffolder-backend-module-azure < 0.2.25
- pkg:npm/%40backstage/plugin-scaffolder-backend-module-bitbucket-cloud < 0.3.10
- pkg:npm/%40backstage/plugin-scaffolder-backend-module-bitbucket-server < 0.2.25
Stated as the source expressed them.
References
- otherOSV webhttps://github.com/backstage/backstage/commit/6fb2a41ea47da37eafe5ea744050ef90be6820c0
- otherOSV webhttps://github.com/backstage/backstage/releases/tag/v1.54.6
- otherOSV webhttps://github.com/backstage/backstage/security/advisories/GHSA-29gx-h2m3-xw44
- advisoryOSV GHSA-29gx-h2m3-xw44https://osv.dev/vulnerability/GHSA-29gx-h2m3-xw44
- advisoryOSV advisoryhttps://nvd.nist.gov/vuln/detail/CVE-2026-106462
- otherOSV webhttps://github.com/backstage/backstage/commit/6fb2a41ea47da37eafe5ea744050
- vendorOSV packagehttps://github.com/backstage/backstage
Related threats
same CWE or vendorCVE-2026-107782 — System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach pri…
CVE-2026-107782 · 3h ago
CVE-2026-107706 — Dolibarr ERP CRM before 24.0.2 contains an incorrect authorization vulnerability in htdocs/core/ajax/updateextrafield.php that checks only read per…
CVE-2026-107706 · 4h ago
CVE-2026-107392 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107392 · 4h ago
CVE-2026-107391 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107391 · 4h ago
CVE-2026-107389 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107389 · 4h ago
CVE-2026-107388 — music-metadata is a metadata parser for audio and video media files.
CVE-2026-107388 · 5h ago