CVE-2026-106488: Backstage: Improper authentication in the OIDC provider
Impact
Deployments using OIDC email-based identity resolution with a provider that permits unverified email addresses may allow an authenticated provider user to assume another catalog identity. This may grant access and permissions associated with that user. No direct availability impact is demonstrated.
Patches
Patched in @backstage/plugin-auth-backend-module-oidc-provider version 0.4.20.
Workarounds
- Disable email-based sign-in resolution for the OIDC provider, or require the identity provider to verify email addresses before allowing sign-in.
Other sources
Backstage is an open framework for building developer portals. Prior to 0.4.20, the @backstage/plugin-auth-backend-module-oidc-provider package is affected by improper authentication in the oidc provider. Deployments using OIDC email-based identity resolution with a provider that permits unverified email addresses may allow an authenticated provider user to assume another catalog identity. This may grant access and permissions associated with that user. No direct availability impact is demonstrated. This issue is fixed in version 0.4.20.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-auth-backend-module-oidc-providerto a version that resolves this vulnerability.Fixed in 0.4.20 - Upgrade
Upgrade
@backstage/plugin-auth-backend-module-oidc-providerto a version that resolves this vulnerability.Fixed in 0.4.20 - Configuration
Disable email-based sign-in resolution for the OIDC provider, or require the identity provider to verify email addresses before allowing sign-in.
OIDC provider email-based sign-in resolution = disabled
Event History
Frequently Asked Questions
Which deployments are exposed to identity impersonation?
Deployments using @backstage/plugin-auth-backend-module-oidc-provider before 0.4.20 are affected when they use email-based identity resolution and their OIDC provider permits unverified email addresses.
What does an attacker need to exploit this issue?
The attacker needs to be able to authenticate as a user with the OIDC provider. If the provider accepts unverified email addresses, the attacker may be able to use an email matching another catalog identity and obtain that identity's access and permissions.
What is the remediation?
Upgrade @backstage/plugin-auth-backend-module-oidc-provider to version 0.4.20 or later. If upgrading cannot happen immediately, the provided information indicates that exposure depends on preventing use of unverified email addresses with email-based identity resolution.
Is service availability affected?
No direct availability impact has been demonstrated. The documented impact is unauthorized access to another catalog identity's permissions.