CVE-2026-106492: Backstage: Improper preservation of access restrictions during service credential delegation
Impact
An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for.
Patches
Patched in @backstage/backend-defaults version 0.17.8
Workarounds
If you're unable to upgrade immediately:
- If practical, replace restricted credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers. - Restrict network-level access to Backstage backend API endpoints to trusted callers only.
Other sources
Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for. This issue is fixed in versions 0.16.1 and 0.17.8.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.17.8 - Upgrade
Upgrade
@backstage/backend-defaultsto a version that resolves this vulnerability.Fixed in 0.17.8 - Compensating control
Replace restricted external service credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers.
- Compensating control
Restrict network-level access to Backstage backend API endpoints to trusted callers only.
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using @backstage/backend-defaults before version 0.16.1 or 0.17.8 are affected when they use external service credentials with access restrictions and plugin delegation paths.
What does exploitation require?
An attacker needs an external service credential that is intended to be restricted, such as read-only access. They can route requests through plugin delegation paths to perform operations beyond that credential's intended scope.
What should be done to remediate the issue?
Upgrade @backstage/backend-defaults to version 0.16.1 or 0.17.8, which contain the fix.