CVE-2026-106461: Backstage: Incorrect authorization in scaffolder task listing
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by incorrect authorization in scaffolder task listing. An authenticated internal user may be able to view metadata for scaffolder tasks outside the visibility intended by a deployment's permission policy. Stored task secrets are not included in the affected response, and no integrity or availability impact was identified. This issue is fixed in version 4.1.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated internal user can potentially view metadata for scaffolder tasks that should be hidden by the deployment's permission policy. The provided information does not indicate that unauthenticated users can exploit it.
What information is exposed, and are task secrets included?
The exposure is limited to scaffolder task metadata. Stored task secrets are not included in the affected response, and no integrity or availability impact was identified.
Which versions are affected and what is the fix?
Versions of @backstage/plugin-scaffolder-backend prior to 4.1.0 are affected. Upgrade the package to version 4.1.0 to remediate the authorization issue.