Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-106501: Backstage scaffolder may reveal other users' credentials
CVE-2026-106501 · published 3 days ago
Summary
If you run Backstage versions before 3.3.1, 3.4.1, 4.0.3, or 4.1.0, a signed‑in user can see internal data from another user's scaffolding task. That data can include passwords or keys for external services, exposing them to unauthorized use. Update the Backstage scaffolder plugin to the fixed releases to stop the data leak.
What to do
- Update backstage plugin-scaffolder-backend to version 3.3.1.
- Update backstage plugin-scaffolder-backend to version 3.4.1.
- Update backstage plugin-scaffolder-backend to version 4.0.3.
- Update backstage plugin-scaffolder-backend to version 4.1.0.
- Update backstage @backstage/plugin-scaffolder-backend to version 3.3.1.
- Update backstage @backstage/plugin-scaffolder-backend to version 3.4.1.
- Update backstage @backstage/plugin-scaffolder-backend to version 4.0.3.
- Update backstage @backstage/plugin-scaffolder-backend to version 4.1.0.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | backstage | backstage | < 1.49.6 |
| – | @backstage | plugin-scaffolder-backend | < 3.3.1 |
| npm | backstage | plugin-scaffolder-backend |
< 3.3.1 >= 3.4.0, < 3.4.1 >= 4.0.0, < 4.0.3 >= 4.0.4, < 4.1.0 Fix: upgrade to 3.3.1
|
| npm | backstage | @backstage/plugin-scaffolder-backend |
< 3.3.1 >= 3.4.0, < 3.4.1 >= 4.0.0, < 4.0.3 >= 4.0.4, < 4.1.0 Fix: upgrade to 3.3.1
|
Original advisory text
Backstage: Sensitive information exposure in Scaffolder
Backstage is an open framework for building developer portals. Prior to 3.3.1, 3.4.1, 4.0.3 and 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by sensitive information exposure in scaffolder. An authenticated Backstage user who can read another user's Scaffolder task may receive internal execution data. In deployments where that data contains credentials for an external service, this may permit disclosure and unauthorized changes in that external service. This issue is fixed in versions 3.3.1, 3.4.1, 4.0.3 and 4.1.0.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-1065... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-106501 Vendor Advisory
- https://github.com/advisories/GHSA-g2v8-7jhw-pp8p
- https://github.com/backstage/backstage Product
- https://github.com/backstage/backstage/security/advisories/GHSA-g2v8-7jhw-pp8p
- https://github.com/backstage/backstage/commit/66d2219edf0abe33ab7d0c1ced5d069d1e...
- https://github.com/backstage/backstage/commit/c19838870476a8e29144c84b1a5ac0654e...
- https://github.com/backstage/backstage/commit/e262d649981ff99bb01ca7077807ae3e25...
- https://github.com/backstage/backstage/releases/tag/v1.49.6
- https://github.com/backstage/backstage/releases/tag/v1.50.5
- https://github.com/backstage/backstage/releases/tag/v1.54.6
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-200Information Exposure
CWE-201Insertion of Sensitive Information Into Sent Data
Timeline
Published6 Oct 2026
Updated9 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-106501 · NVD
CVE-2026-106501 · MITRE
CVE-2026-106501 · OSV
GHSA-g2v8-7jhw-pp8p · GHSA
GHSA-g2v8-7jhw-pp8p · OSV
Track software like this
Free during beta