๐Ÿ” CVE Alert

CVE-2026-106457

MEDIUM 6.8

Backstage: Insufficient audience validation in the Cloudflare Access auth provider

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature and team issuer, but affected versions do not verify that the token was issued for the Backstage application. A user holding a valid token for another Access application in the same Cloudflare Zero Trust team may therefore be able to authenticate to Backstage if that token reaches the auth endpoint without the Backstage application's audience already being enforced upstream. Cloudflare Access normally evaluates the protected application before forwarding requests. This issue is fixed in version 0.5.0.

CWE CWE-287
Vendor backstage
Product backstage
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for backstage backstage

Be the first to know when new medium vulnerabilities affecting backstage backstage are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

backstage / backstage
>= 1.26.0, < 1.55.0
@backstage / plugin-auth-backend-module-cloudflare-access-provider
>= 0.1.0, < 0.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/backstage/backstage/security/advisories/GHSA-q333-f498-w2x7 github.com: https://github.com/backstage/backstage/commit/ed9034cacd9def3b3674f0a764fe992f751e204d github.com: https://github.com/backstage/backstage/releases/tag/v1.55.0