CVE-2026-106490: Backstage: Improper input validation in TechDocs static content requests
Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper input validation in techdocs static content requests. When using the Azure Blob Storage provider, an authenticated Backstage user may be able to read restricted TechDocs content when entity-level permissions are enabled. Deployments that intentionally disable the default backend authentication policy may have broader exposure. This issue is fixed in version 2.2.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-techdocs-backendto a version that resolves this vulnerability.Fixed in 2.2.4
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects @backstage/plugin-techdocs-backend versions prior to 2.2.4 when the Azure Blob Storage provider is used. Entity-level permissions must be enabled for the described restricted-content access scenario.
What does an attacker need to exploit this issue?
An attacker needs to be an authenticated Backstage user. No user interaction is required.
Does disabling backend authentication change the exposure?
Yes. Deployments that intentionally disable the default backend authentication policy may have broader exposure than the authenticated-user scenario described.
What version fixes the issue?
Upgrade @backstage/plugin-techdocs-backend to version 2.2.4.