Backstage 是一个用于构建开发者门户的开源框架。在版本 0.4.20 之前,@backstage/plugin-auth-backend-module-oidc-provider 包中存在 OIDC 提供商身份验证不当的问题。如果部署使用了 OIDC 基于电子邮件的身份解析,并且所配置的 OIDC 提供商允许使用未经核实的电子邮件地址,则已认证的提供商用户可能会冒充目录(Catalog)中的另一个用户身份。这可能导致攻击者获得与该冒充用户关联的访问权限和权限级别。目前没有证据表明该漏洞会直接影响系统的可用性
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| backstage | backstage | < 1.54.6 | - |
|
| @backstage | plugin-auth-backend-module-oidc-provider | < 0.4.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106486 | 8.5 HIGH | Backstage: Improper filesystem validation in Bitbucket pull-request scaffolder actions |
| CVE-2026-106459 | 8.5 HIGH | Backstage: Improper input validation in Sentry scaffolder actions |
| CVE-2026-106455 | 7.7 HIGH | Backstage: Improper validation of MkDocs plugin configuration in TechDocs |
| CVE-2026-106492 | 7.6 HIGH | Backstage: Improper preservation of access restrictions during service credential delegati |
| CVE-2026-106460 | 6.8 MEDIUM | Backstage: Explicit negative email verification can be ignored during shared OAuth profile |
| CVE-2026-106457 | 6.8 MEDIUM | Backstage: Insufficient audience validation in the Cloudflare Access auth provider |
| CVE-2026-106458 | 6.5 MEDIUM | Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates |
| CVE-2026-106490 | 6.5 MEDIUM | Backstage: Improper input validation in TechDocs static content requests |
| CVE-2026-106489 | 6.5 MEDIUM | Backstage: Improper authorization enforcement for TechDocs static content |
| CVE-2026-106462 | 6.4 MEDIUM | Backstage: Scaffolder credential handling may allow unintended GitHub authentication fallb |
| CVE-2026-106491 | 6.4 MEDIUM | Backstage: Improper input validation in proxy-backend |
| CVE-2026-106463 | 5.4 MEDIUM | Backstage: Improper authorization in GitLab organizational user ingestion |
| CVE-2026-106456 | 4.8 MEDIUM | Backstage: Inconsistent credential enforcement for overlapping proxy routes |
| CVE-2026-106494 | 4.4 MEDIUM | Backstage: Improper input validation in cloud storage URL readers |
| CVE-2026-106461 | 4.3 MEDIUM | Backstage: Incorrect authorization in scaffolder task listing |
| CVE-2026-106487 | 3.5 LOW | Backstage: Unsupported catalog cluster authentication mode in kubernetes backend |
| CVE-2026-106493 | 3.0 LOW | Backstage: Cloud storage catalog locations may cross configured storage boundaries |
No comments yet