CVE-2026-106492: Backstage: Improper preservation of access restrictions during service credential delegation
### Impact An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for. ### Patches Patched in `@backstage/backend-defaults` version `0.17.8` ### Workarounds If you're unable to upgrade immediately: - If practical, replace restricted credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers. - Restrict network-level access to Backstage backend API endpoints to trusted callers only.
Recommended action
Recommended action
Upgrade affected packages to a patched version: @backstage/backend-defaults 0.17.8.
Technical details
- Vendor
- Not specified
- Product
- @backstage/backend-defaults
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source