2026-10-06 21:37CVE-2026-106503GitHub_M
PUBLISHED5.2CWE-178CWE-284

Backstage: Scaffolder action input authorization bypass

Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authorization bypass. An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.

Problem type

Affected products

backstage

backstage

< 1.49.6 - AFFECTED

>= 1.50.0-next.0, < 1.50.5 - AFFECTED

>= 1.51.0-next.0, < 1.54.6 - AFFECTED

@backstage

plugin-scaffolder-backend

< 3.3.1 - AFFECTED

>= 3.4.0, < 3.4.1 - AFFECTED

>= 4.0.0, < 4.0.3 - AFFECTED

>= 4.0.4, < 4.1.0 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-106503
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-106503",
    "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
    "assignerShortName": "GitHub_M",
    "dateUpdated": "2026-10-06T21:37:33.675Z",
    "dateReserved": "2026-10-06T18:46:47.766Z",
    "datePublished": "2026-10-06T21:37:33.675Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "shortName": "GitHub_M",
        "dateUpdated": "2026-10-06T21:37:33.675Z"
      },
      "title": "Backstage: Scaffolder action input authorization bypass",
      "descriptions": [
        {
          "lang": "en",
          "value": "Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by scaffolder action input authorization bypass. An authenticated user with access to affected Scaffolder templates could bypass configured action restrictions. Depending on integration credentials, this could grant unauthorized access to repositories and related source-control resources. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0."
        }
      ],
      "affected": [
        {
          "vendor": "backstage",
          "product": "backstage",
          "versions": [
            {
              "version": "< 1.49.6",
              "status": "affected"
            },
            {
              "version": ">= 1.50.0-next.0, < 1.50.5",
              "status": "affected"
            },
            {
              "version": ">= 1.51.0-next.0, < 1.54.6",
              "status": "affected"
            }
          ]
        },
        {
          "vendor": "@backstage",
          "product": "plugin-scaffolder-backend",
          "versions": [
            {
              "version": "< 3.3.1",
              "status": "affected"
            },
            {
              "version": ">= 3.4.0, < 3.4.1",
              "status": "affected"
            },
            {
              "version": ">= 4.0.0, < 4.0.3",
              "status": "affected"
            },
            {
              "version": ">= 4.0.4, < 4.1.0",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-178: Improper Handling of Case Sensitivity",
              "cweId": "CWE-178",
              "type": "CWE"
            }
          ]
        },
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-284: Improper Access Control",
              "cweId": "CWE-284",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/backstage/backstage/security/advisories/GHSA-hmp2-4m7g-22cv",
          "name": "https://github.com/backstage/backstage/security/advisories/GHSA-hmp2-4m7g-22cv",
          "tags": [
            "x_refsource_CONFIRM"
          ]
        },
        {
          "url": "https://github.com/backstage/backstage/commit/11c1384c0649b8ab26391c6a4e4f34b80ab0d188",
          "name": "https://github.com/backstage/backstage/commit/11c1384c0649b8ab26391c6a4e4f34b80ab0d188",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/backstage/backstage/commit/a91ed72d540e80b62a73b39bb1563ff5018d52d1",
          "name": "https://github.com/backstage/backstage/commit/a91ed72d540e80b62a73b39bb1563ff5018d52d1",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/backstage/backstage/commit/e307e4f487103d815e484291b3fda778ab9983bf",
          "name": "https://github.com/backstage/backstage/commit/e307e4f487103d815e484291b3fda778ab9983bf",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/backstage/backstage/releases/tag/v1.49.6",
          "name": "https://github.com/backstage/backstage/releases/tag/v1.49.6",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/backstage/backstage/releases/tag/v1.50.5",
          "name": "https://github.com/backstage/backstage/releases/tag/v1.50.5",
          "tags": [
            "x_refsource_MISC"
          ]
        },
        {
          "url": "https://github.com/backstage/backstage/releases/tag/v1.54.6",
          "name": "https://github.com/backstage/backstage/releases/tag/v1.54.6",
          "tags": [
            "x_refsource_MISC"
          ]
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "LOW",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH"
          }
        }
      ]
    }
  }
}