CVE-2026-106489: Backstage: Improper authorization enforcement for TechDocs static content
Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper authorization enforcement for techdocs static content. An authenticated user with access to one TechDocs documentation site could craft a URL able to read documentation belonging to a different entity. This only affects deployments using the external TechDocs builder with an external storage provider (S3, GCS, etc.) and the permission framework enabled. Instances that do not use the permission framework are unaffected, since TechDocs content is visible to all authenticated users by design. This issue is fixed in version 2.2.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-techdocs-backendto a version that resolves this vulnerability.Fixed in 2.2.4
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments use @backstage/plugin-techdocs-backend before 2.2.4, the external TechDocs builder, an external storage provider such as S3 or GCS, and the permission framework. Deployments without the permission framework are unaffected because TechDocs content is intentionally visible to all authenticated users.
What access does an attacker need?
An attacker must be authenticated and have access to at least one TechDocs documentation site. They can then craft a URL to read documentation associated with a different entity.
What is the remediation?
Upgrade @backstage/plugin-techdocs-backend to version 2.2.4, which fixes the authorization enforcement issue.