<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Backstage - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/backstage/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:55:19 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/backstage/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Authentication Vulnerability in Backstage OIDC Provider</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-oidc-auth/</link><pubDate>Wed, 07 Oct 2026 22:55:19 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-oidc-auth/</guid><description>A vulnerability in the Backstage OIDC authentication module allows authenticated users to spoof identities when using email-based resolution with unverified email providers, leading to unauthorized access.</description><content:encoded><![CDATA[<p>Backstage's <code>@backstage/plugin-auth-backend-module-oidc-provider</code> is affected by an improper authentication vulnerability, tracked as CVE-2026-106488. The flaw exists in the email-based identity resolution process when configured with OIDC providers that do not enforce email verification. An attacker who is authenticated via a malicious or misconfigured OIDC provider can supply an unverified email address that matches an existing user in the Backstage catalog. The application incorrectly maps the attacker's session to the identity of the victim user, allowing for full impersonation of that user's identity and associated permissions within the Backstage environment. This vulnerability affects versions prior to 0.4.20. Defenders should note that this vulnerability does not represent a code injection or direct system compromise, but rather a logic flaw in how identity claims are validated during the OIDC handshake.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for unauthorized access to catalog entities and sensitive resources managed by Backstage by assuming the identity of another user. This can lead to privilege escalation if the spoofed user account holds administrative roles or high-level access to internal developer portal documentation, service metadata, or infrastructure configurations. No specific victim counts have been reported, but organizations utilizing email-based OIDC identity resolution are at risk if their provider allows unverified addresses.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the <code>@backstage/plugin-auth-backend-module-oidc-provider</code> package to version 0.4.20 or later to include the patch for CVE-2026-106488.</li>
<li>Review OIDC provider configurations and disable email-based identity resolution if email verification cannot be strictly enforced at the provider level.</li>
<li>Monitor authentication logs for unexpected account mappings or user sessions originating from non-standard or untrusted OIDC provider issuers.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authentication-bypass</category><category>cve-2026-106488</category><category>backstage</category></item><item><title>Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Modules</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-path-traversal/</link><pubDate>Wed, 07 Oct 2026 22:54:58 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-path-traversal/</guid><description>Authenticated users can exploit improper filesystem validation in Backstage Bitbucket scaffolder plugins to achieve unauthorized file access, modification, or deletion outside the intended working directory via CVE-2026-106486.</description><content:encoded><![CDATA[<p>The Backstage Scaffolder backend modules for Bitbucket Cloud and Bitbucket Server contain an improper filesystem validation vulnerability, tracked as CVE-2026-106486. This flaw exists within the scaffolder actions responsible for interacting with Bitbucket repositories. An authenticated user who has the privileges to execute templates and the ability to influence the targeted Bitbucket repository parameter can supply malicious input to traverse the filesystem on the backend host. By manipulating these inputs, an attacker may escape the expected working directory, potentially reading sensitive configuration files, modifying application code, or deleting arbitrary files. This vulnerability poses a significant risk to backend integrity and confidentiality, particularly in environments where untrusted users have template creation or execution access.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated attacker to perform unauthorized file operations on the host running the Backstage backend. This can result in the compromise of backend confidentiality (sensitive file exfiltration), integrity (malicious code injection), or availability (system file deletion). The scope of impact is limited by the permissions of the process running the Backstage backend service.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade <code>@backstage/plugin-scaffolder-backend-module-bitbucket-cloud</code> to version 0.3.10 or later.</li>
<li>Upgrade <code>@backstage/plugin-scaffolder-backend-module-bitbucket-server</code> to version 0.2.25 or later.</li>
<li>Apply administrative restrictions on Scaffolder template execution, limiting them to trusted users only.</li>
<li>Audit existing Scaffolder templates to identify and restrict actions that accept user-controlled target repository inputs until patching is complete.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>path-traversal</category><category>backstage</category><category>vulnerability</category><category>cve-2026-106486</category></item><item><title>Sensitive Information Exposure in Backstage Scaffolder Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-backstage-exposure/</link><pubDate>Wed, 07 Oct 2026 22:47:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-backstage-exposure/</guid><description>An authenticated user can access internal task execution data in Backstage, potentially exposing credentials stored within Scaffolder tasks to unauthorized parties.</description><content:encoded><![CDATA[<p>The Backstage Scaffolder plugin (specifically @backstage/plugin-scaffolder-backend) contains a vulnerability identified as CVE-2026-106501, which allows for unauthorized access to sensitive internal execution data. An authenticated user within the Backstage environment can perform read operations on Scaffolder tasks created by other users. If these tasks contain sensitive execution metadata, such as hardcoded credentials or API keys used for external service integration, this information is disclosed. The exposure of these credentials can lead to unauthorized access, modifications, or data exfiltration within the downstream external services integrated into the Backstage workflow. This vulnerability affects multiple versions of the plugin prior to 4.1.0, requiring either an immediate upgrade or the implementation of specific task-read access controls to mitigate unauthorized access to sensitive workflows.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a critical risk to organizations relying on Backstage for service orchestration and workflow automation. If successfully exploited, attackers or malicious insiders can obtain privileged credentials that permit unauthorized interaction with integrated third-party systems. This can result in significant data breaches or unauthorized system state changes across the organization's cloud and development infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade @backstage/plugin-scaffolder-backend to version 4.1.0 or later immediately to patch CVE-2026-106501.</li>
<li>If an upgrade is not immediately possible, modify the Scaffolder configuration to apply the <code>isTaskOwner</code> condition to <code>scaffolder.task.read</code>, ensuring that users are restricted to viewing only their own tasks.</li>
<li>Audit active Scaffolder workflows and their integrated services for any potentially compromised credentials that may have been exposed through unauthorized task access.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>cloud-native</category><category>backstage</category><category>cve</category><category>rce</category><category>privilege-escalation</category></item></channel></rss>