CVE-2026-106457: Backstage: Insufficient audience validation in the Cloudflare Access auth provider
Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature and team issuer, but affected versions do not verify that the token was issued for the Backstage application. A user holding a valid token for another Access application in the same Cloudflare Zero Trust team may therefore be able to authenticate to Backstage if that token reaches the auth endpoint without the Backstage application's audience already being enforced upstream. Cloudflare Access normally evaluates the protected application before forwarding requests. This issue is fixed in version 0.5.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-auth-backend-module-cloudflare-access-providerto a version that resolves this vulnerability.Fixed in 0.5.0
Event History
Frequently Asked Questions
Which deployments are realistically exposed?
Deployments using @backstage/plugin-auth-backend-module-cloudflare-access-provider from 0.1.0 through versions before 0.5.0 are affected when the Backstage auth endpoint can receive Cloudflare Access tokens without upstream enforcement of the Backstage application's audience. Cloudflare Access normally evaluates the protected application before forwarding requests.
What does an attacker need to exploit this?
An attacker needs a valid Cloudflare Access token issued for another Access application in the same Cloudflare Zero Trust team, and must be able to send that token to the Backstage auth endpoint. The affected provider validates the token signature and team issuer but not that it was issued for the Backstage application.
What remediation is available?
Upgrade @backstage/plugin-auth-backend-module-cloudflare-access-provider to version 0.5.0, which fixes the issue. If upgrading is not immediately possible, ensure the Backstage application's audience is enforced upstream before requests reach the auth endpoint.