CVE-2026-106457: medium-severity vulnerability in backstage
Backstage: Insufficient audience validation in the Cloudflare Access auth provider
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.8epss 0.3%
exploitation probability
0.3%top 82% of all CVEs
observed exploitation
nono source reports it
Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature and team issuer, but affected versions do not verify that the token was issued for the Backstage application. A user holding a valid token for another Access application in the same Cloudflare Zero Trust team may therefore be able to authenticate to Backstage if that token reaches the auth endpoint without the Backstage application's audience already being enforced upstream. Cloudflare Access normally evaluates the protected application before forwarding requests. This issue is fixed in version 0.5.0.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
@backstage · plugin-auth-backend-module-cloudflare-access-providerbackstage · backstageRelated CVEs — backstage
In the same product, most dangerous first.
CVE-2023-35926HIGHInsecure sandbox in Backstage Scaffolder pluginEPSS 1.9%CVE-2021-41151MEDIUMPath Traversal in @backstage/plugin-scaffolder-backendEPSS 1.3%CVE-2021-32662MEDIUMTechDocs mkdocs.yml path traversalEPSS 1.3%CVE-2021-32660MEDIUMTechDocs content sanitization bypassEPSS 1.3%CVE-2021-43783HIGHPath Traversal in @backstage/plugin-scaffolder-backendEPSS 1.2%CVE-2021-32661MEDIUMTechDocs object element script injectionEPSS 1.2%