Backstage 是一个用于构建开发者门户的开源框架。在版本 0.3.0 至 0.6.14 以及 0.7.0 至 0.7.4 中, 包在共享 OAuth 个人资料规范化过程中,未始终如一地尊重显式的电子邮件验证否定状态。受影响的场景包括:已选个人资料中标记为 的电子邮件、匹配原始提供商电子邮件标记为 的场景,以及仅从 ID token 获取且标记为 的电子邮件。 漏洞利用需要满足以下条件: 1. 存在一个已通过的身份提供商用户,该用户能够提供或更改未经过验证的电子邮件地址; 2. 部署配置中使用“已选个人资料电子
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| backstage | backstage | >= 1.18.0, < 1.49.7 | - |
|
| @backstage | plugin-auth-node | >= 0.3.0, < 0.6.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106459 | 8.5 HIGH | Backstage: Improper input validation in Sentry scaffolder actions |
| CVE-2026-106486 | 8.5 HIGH | Backstage: Improper filesystem validation in Bitbucket pull-request scaffolder actions |
| CVE-2026-106488 | 8.1 HIGH | Backstage: Improper authentication in the OIDC provider |
| CVE-2026-106455 | 7.7 HIGH | Backstage: Improper validation of MkDocs plugin configuration in TechDocs |
| CVE-2026-106492 | 7.6 HIGH | Backstage: Improper preservation of access restrictions during service credential delegati |
| CVE-2026-106457 | 6.8 MEDIUM | Backstage: Insufficient audience validation in the Cloudflare Access auth provider |
| CVE-2026-106458 | 6.5 MEDIUM | Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates |
| CVE-2026-106490 | 6.5 MEDIUM | Backstage: Improper input validation in TechDocs static content requests |
| CVE-2026-106489 | 6.5 MEDIUM | Backstage: Improper authorization enforcement for TechDocs static content |
| CVE-2026-106462 | 6.4 MEDIUM | Backstage: Scaffolder credential handling may allow unintended GitHub authentication fallb |
| CVE-2026-106491 | 6.4 MEDIUM | Backstage: Improper input validation in proxy-backend |
| CVE-2026-106463 | 5.4 MEDIUM | Backstage: Improper authorization in GitLab organizational user ingestion |
| CVE-2026-106456 | 4.8 MEDIUM | Backstage: Inconsistent credential enforcement for overlapping proxy routes |
| CVE-2026-106494 | 4.4 MEDIUM | Backstage: Improper input validation in cloud storage URL readers |
| CVE-2026-106461 | 4.3 MEDIUM | Backstage: Incorrect authorization in scaffolder task listing |
| CVE-2026-106487 | 3.5 LOW | Backstage: Unsupported catalog cluster authentication mode in kubernetes backend |
| CVE-2026-106493 | 3.0 LOW | Backstage: Cloud storage catalog locations may cross configured storage boundaries |
No comments yet