CVE-2026-106503
Received
Received - Intake
Scaffolder Action Input Authorization Bypass in Backstage
Vulnerability report for CVE-2026-106503, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: GitHub, Inc.
Description
Description
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authorization bypass. An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| backstage | backstage | < 1.49.6 |
| backstage | backstage | >= 1.50.0-next.0, < 1.50.5 |
| backstage | backstage | >= 1.51.0-next.0, < 1.54.6 |
| @backstage | plugin-scaffolder-backend | < 3.3.1 |
| @backstage | plugin-scaffolder-backend | >= 3.4.0, < 3.4.1 |
| @backstage | plugin-scaffolder-backend | >= 4.0.0, < 4.0.3 |
| @backstage | plugin-scaffolder-backend | >= 4.0.4, < 4.1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-178 | The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results. |
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |