PT-2026-107269 · Backstage · Backstage

CVE-2026-106488

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Backstage versions prior to 0.4.20
Description The @backstage/plugin-auth-backend-module-oidc-provider package contains improper authentication within the OIDC provider. In deployments utilizing OIDC email-based identity resolution with a provider that allows unverified email addresses, an authenticated user may be able to assume another catalog identity, potentially gaining the access and permissions associated with that user.
Recommendations Update to version 0.4.20.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106488
GHSA-826H-28H9-65HG

Affected Products

Backstage