Vendor
Improper URL Validation in Backstage Catalog Entity Placeholder Resolution
1 CVEAn authenticated user can exploit improper URL validation in Backstage plugin-catalog-backend to access unauthorized resources outside the intended source repository via crafted catalog entity placeholder directives.
Improper Access Restriction Enforcement in Backstage Service Delegation
1 TTP 1 CVEA vulnerability in Backstage's backend-defaults package allows restricted service credentials to bypass defined access restrictions when routing requests through plugin delegation paths, potentially leading to unauthorized privilege escalation.
Improper Authentication Vulnerability in Backstage OIDC Provider
1 TTP 1 CVEA vulnerability in the Backstage OIDC authentication module allows authenticated users to spoof identities when using email-based resolution with unverified email providers, leading to unauthorized access.
Path Traversal Vulnerability in Backstage Bitbucket Scaffolder Modules
1 TTP 1 CVEAuthenticated users can exploit improper filesystem validation in Backstage Bitbucket scaffolder plugins to achieve unauthorized file access, modification, or deletion outside the intended working directory via CVE-2026-106486.
Improper Input Validation in Backstage Sentry Scaffolder Module
2 TTPs 1 CVEAn authenticated internal user can exploit improper input validation in the Backstage Sentry scaffolder module to trigger SSRF and disclose sensitive integration credentials.
Sensitive Information Exposure in Backstage Scaffolder Plugin
2 TTPs 1 CVEAn authenticated user can access internal task execution data in Backstage, potentially exposing credentials stored within Scaffolder tasks to unauthorized parties.
Remote Code Execution in Backstage TechDocs via Malicious MkDocs Configuration
3 TTPs 1 CVEAn improper input validation vulnerability (CVE-2026-106509) in Backstage plugin-techdocs-node allows authenticated users to achieve arbitrary code execution via crafted mkdocs.yml files.