CVE-2026-106503: Backstage: Scaffolder action input authorization bypass
Impact
An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources.
Patches
Patched in @backstage/plugin-scaffolder-backend version 4.1.0
Workarounds
- Restrict affected Scaffolder actions to trusted users and configure source-control integrations with least-privilege credentials.
Other sources
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authorization bypass. An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.0.3 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 3.4.1 - Upgrade
Upgrade
npm/@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 3.3.1 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.1.0 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 3.3.1 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 3.4.1 - Upgrade
Upgrade
@backstage/plugin-scaffolder-backendto a version that resolves this vulnerability.Fixed in 4.0.3 - Compensating control
Restrict affected Scaffolder actions to trusted users and configure source-control integrations with least-privilege credentials.
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated user who has access to affected Scaffolder templates can exploit the authorization bypass. The issue affects the @backstage/plugin-scaffolder-backend package before versions 3.3.1, 3.4.1, 4.0.3, and 4.1.0.
What level of access could an attacker gain?
Configured action restrictions can be bypassed. Depending on the integration credentials available to the affected Backstage deployment, this may provide unauthorized access to repositories and related source-control resources.
Which versions contain fixes?
The issue is fixed in versions 3.3.1, 3.4.1, 4.0.3, and 4.1.0 of @backstage/plugin-scaffolder-backend.