PT-2026-107270 · Backstage · Backstage

CVE-2026-106489

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Backstage versions prior to 2.2.4
Description The @backstage/plugin-techdocs-backend package contains improper authorization enforcement for static content. An authenticated user with access to one TechDocs documentation site can craft a URL to read documentation belonging to a different entity. This issue specifically affects deployments that utilize the external TechDocs builder with an external storage provider (such as S3 or GCS) and have the permission framework enabled.
Recommendations Update to version 2.2.4.

Exploit

Fix

Path traversal

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106489
GHSA-RG9R-HR7G-5GC2

Affected Products

Backstage