Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-106501: Backstage scaffolder may reveal other users' credentials

CVE-2026-106501 · published 3 days ago
Summary

If you run Backstage versions before 3.3.1, 3.4.1, 4.0.3, or 4.1.0, a signed‑in user can see internal data from another user's scaffolding task. That data can include passwords or keys for external services, exposing them to unauthorized use. Update the Backstage scaffolder plugin to the fixed releases to stop the data leak.

What to do
  • Update backstage plugin-scaffolder-backend to version 3.3.1.
  • Update backstage plugin-scaffolder-backend to version 3.4.1.
  • Update backstage plugin-scaffolder-backend to version 4.0.3.
  • Update backstage plugin-scaffolder-backend to version 4.1.0.
  • Update backstage @backstage/plugin-scaffolder-backend to version 3.3.1.
  • Update backstage @backstage/plugin-scaffolder-backend to version 3.4.1.
  • Update backstage @backstage/plugin-scaffolder-backend to version 4.0.3.
  • Update backstage @backstage/plugin-scaffolder-backend to version 4.1.0.
Affected software
Ecosystem VendorProductAffected versions
– backstage backstage < 1.49.6
– @backstage plugin-scaffolder-backend < 3.3.1
npm backstage plugin-scaffolder-backend < 3.3.1
>= 3.4.0, < 3.4.1
>= 4.0.0, < 4.0.3
>= 4.0.4, < 4.1.0
Fix: upgrade to 3.3.1
npm backstage @backstage/plugin-scaffolder-backend < 3.3.1
>= 3.4.0, < 3.4.1
>= 4.0.0, < 4.0.3
>= 4.0.4, < 4.1.0
Fix: upgrade to 3.3.1
Original advisory text
Backstage: Sensitive information exposure in Scaffolder
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data. In deployments where that data contains credentials for an external service, this may permit disclosure and unauthorized changes in that external service. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.6 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-200Information Exposure
CWE-201Insertion of Sensitive Information Into Sent Data
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Track software like this
Free during beta