CVE-2026-106492: Backstage: Improper preservation of access restrictions during service credential delegation

Published Oct 6, 2026
·
Updated

Impact

An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for.

Patches

Patched in @backstage/backend-defaults version 0.17.8

Workarounds

If you're unable to upgrade immediately:

- If practical, replace restricted credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers. - Restrict network-level access to Backstage backend API endpoints to trusted callers only.

Other sources

Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for. This issue is fixed in versions 0.16.1 and 0.17.8.

— MITRE

Affected Software

2 affected componentsFixes available
npm/@backstage/backend-defaults<0.16.1, >=0.17.0<0.17.8
npm/@backstage/backend-defaults<0.17.8
0.17.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/backend-defaults to a version that resolves this vulnerability.

    Fixed in 0.17.8
  2. Upgrade

    Upgrade @backstage/backend-defaults to a version that resolves this vulnerability.

    Fixed in 0.17.8
  3. Compensating control

    Replace restricted external service credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers.

  4. Compensating control

    Restrict network-level access to Backstage backend API endpoints to trusted callers only.

Event History

Oct 6, 2026
CVE Published
via MITRE·08:48 PM
Data Sourced
via MITRE·08:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Oct 7, 2026
Advisory Published
via GitHub·05:59 PM
Data Sourced
via GitHub·05:59 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Deployments using @backstage/backend-defaults before version 0.16.1 or 0.17.8 are affected when they use external service credentials with access restrictions and plugin delegation paths.

2

What does exploitation require?

An attacker needs an external service credential that is intended to be restricted, such as read-only access. They can route requests through plugin delegation paths to perform operations beyond that credential's intended scope.

3

What should be done to remediate the issue?

Upgrade @backstage/backend-defaults to version 0.16.1 or 0.17.8, which contain the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203