OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-106492: Backstage: Improper preservation of access restrictions during service credential delegation

GitHub Advisories · officialPublished Oct 7, 2026Risk 37/100

### Impact An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for. ### Patches Patched in `@backstage/backend-defaults` version `0.17.8` ### Workarounds If you're unable to upgrade immediately: - If practical, replace restricted credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers. - Restrict network-level access to Backstage backend API endpoints to trusted callers only.

Upgrade affected packages to a patched version: @backstage/backend-defaults 0.17.8.

Vendor
Not specified
Product
@backstage/backend-defaults
Exploitation
none known
Evidence
official
CVSS
7.6

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source