CVE-2026-106462: Backstage: Scaffolder credential handling may allow unintended GitHub authentication fallback
Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user could cause an affected action to fall back to broader integration credentials and perform operations with more access than intended. This issue is fixed in 1.54.6 when operators also enable scaffolder.requireScmUserCredentials after upgrading.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Backstageto a version that resolves this vulnerability.Fixed in 1.54.6 - Configuration
Enable scaffolder.requireScmUserCredentials after upgrading to 1.54.6.
Backstage Scaffolder scaffolder.requireScmUserCredentials = enabled
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated Backstage user who can trigger affected scaffolder source-control actions could exploit it. The attacker does not need user interaction, but does need valid access to the Backstage instance.
Are installations affected after upgrading to 1.54.6?
The fix requires both upgrading to Backstage 1.54.6 and enabling scaffolder.requireScmUserCredentials. Upgrading without enabling that setting does not meet the stated remediation condition.
What access could an attacker gain through the fallback?
Affected actions may fall back to broader source-control integration credentials rather than the intended user credentials. This can allow operations with more access than the user should have had.