<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:backstage:backend-Defaults:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3abackstagebackend-defaults/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:55:32 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3abackstagebackend-defaults/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Access Restriction Enforcement in Backstage Service Delegation</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-credential-delegation/</link><pubDate>Wed, 07 Oct 2026 22:55:32 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-credential-delegation/</guid><description>A vulnerability in Backstage's backend-defaults package allows restricted service credentials to bypass defined access restrictions when routing requests through plugin delegation paths, potentially leading to unauthorized privilege escalation.</description><content:encoded><![CDATA[<p>Backstage, an open platform for building developer portals, contains a security vulnerability in the <code>@backstage/backend-defaults</code> package (versions prior to 0.17.8). The issue arises from the improper preservation of access restrictions during service credential delegation. When an external service credential is configured with limited access, such as read-only permissions, the Backstage backend may fail to enforce these constraints when requests are routed through specific plugin delegation paths.</p>
<p>This flaw allows an attacker or a compromised service to perform actions beyond its intended scope, including executing write operations on plugins that were explicitly restricted to read-only access. Because this bypass occurs within the internal delegation logic, the risk is higher in environments where service-to-service authentication relies heavily on delegated credentials. Defenders must prioritize upgrading the vulnerable package or implementing network-level access controls to restrict access to the backend API.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to the integrity of systems integrated with Backstage. If exploited, an attacker could gain unauthorized write access to resources managed by plugins, potentially modifying sensitive configurations or data. This bypass affects organizations using Backstage for service-to-service interactions where granular access control is enforced via credential delegation. The scope of impact is contingent upon the number of plugins relying on these specific delegation paths and the privilege level of the credentials involved.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>@backstage/backend-defaults</code> package to version 0.17.8 or later immediately to address CVE-2026-106492.</li>
<li>If an immediate upgrade is not possible, rotate restricted credentials and replace them with purpose-specific, unrestricted credentials scoped strictly to trusted consumers.</li>
<li>Restrict network-level access to all Backstage backend API endpoints, ensuring only authorized callers and internal services can communicate with the API.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>