CVE-2026-106462
Received
Received - Intake
Backstage Scaffolder Credential Boundary Bypass
Vulnerability report for CVE-2026-106462, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: GitHub, Inc.
Description
Description
Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user could cause an affected action to fall back to broader integration credentials and perform operations with more access than intended. This issue is fixed in 1.54.6 when operators also enable scaffolder.requireScmUserCredentials after upgrading.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| backstage | backstage | < 1.54.6 |
| @backstage | plugin-scaffolder-backend | < 4.1.0 |
| @backstage | plugin-scaffolder-backend-module-azure | < 0.2.25 |
| @backstage | plugin-scaffolder-backend-module-bitbucket-cloud | < 0.3.10 |
| @backstage | plugin-scaffolder-backend-module-bitbucket-server | < 0.2.25 |
| @backstage | plugin-scaffolder-backend-module-github | < 0.9.13 |
| @backstage | plugin-scaffolder-backend-module-gitlab | < 0.11.10 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |
| CWE-441 | The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor. |