{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/backend-defaults--0.17.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:backstage:backend-defaults:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-106492"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["backend-defaults (\u003c 0.17.8)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Backstage"],"content_html":"\u003cp\u003eBackstage, an open platform for building developer portals, contains a security vulnerability in the \u003ccode\u003e@backstage/backend-defaults\u003c/code\u003e package (versions prior to 0.17.8). The issue arises from the improper preservation of access restrictions during service credential delegation. When an external service credential is configured with limited access, such as read-only permissions, the Backstage backend may fail to enforce these constraints when requests are routed through specific plugin delegation paths.\u003c/p\u003e\n\u003cp\u003eThis flaw allows an attacker or a compromised service to perform actions beyond its intended scope, including executing write operations on plugins that were explicitly restricted to read-only access. Because this bypass occurs within the internal delegation logic, the risk is higher in environments where service-to-service authentication relies heavily on delegated credentials. Defenders must prioritize upgrading the vulnerable package or implementing network-level access controls to restrict access to the backend API.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to the integrity of systems integrated with Backstage. If exploited, an attacker could gain unauthorized write access to resources managed by plugins, potentially modifying sensitive configurations or data. This bypass affects organizations using Backstage for service-to-service interactions where granular access control is enforced via credential delegation. The scope of impact is contingent upon the number of plugins relying on these specific delegation paths and the privilege level of the credentials involved.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@backstage/backend-defaults\u003c/code\u003e package to version 0.17.8 or later immediately to address CVE-2026-106492.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is not possible, rotate restricted credentials and replace them with purpose-specific, unrestricted credentials scoped strictly to trusted consumers.\u003c/li\u003e\n\u003cli\u003eRestrict network-level access to all Backstage backend API endpoints, ensuring only authorized callers and internal services can communicate with the API.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-07T22:55:32Z","date_published":"2026-10-07T22:55:32Z","id":"https://feed.craftedsignal.io/briefs/2026-10-backstage-credential-delegation/","summary":"A vulnerability in Backstage's backend-defaults package allows restricted service credentials to bypass defined access restrictions when routing requests through plugin delegation paths, potentially leading to unauthorized privilege escalation.","title":"Improper Access Restriction Enforcement in Backstage Service Delegation","url":"https://feed.craftedsignal.io/briefs/2026-10-backstage-credential-delegation/"}],"language":"en","title":"CraftedSignal Threat Feed - Backend-Defaults (\u003c 0.17.8)","version":"https://jsonfeed.org/version/1.1"}