GHSA-cq7v-rfgc-5c7vHighCVSS 7.6

Backstage: Improper preservation of access restrictions during service credential delegation

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for.

Patches

Patched in @backstage/backend-defaults version 0.17.8

Workarounds

If you're unable to upgrade immediately:

  • If practical, replace restricted credentials with separate, purpose-specific unrestricted credentials scoped to trusted consumers.
  • Restrict network-level access to Backstage backend API endpoints to trusted callers only.

🎯 Affected products1

  • npm/@backstage/backend-defaults:< 0.17.8

🔗 References (7)