Answer in brief
CVE-2026-106462 records a Medium severity (CVSS 6.4) vulnerability in Backstage: Scaffolder credential handling may allow unintended GitHub authentication fallback. The current sources do not mark it as known exploited. The current feed maps backstage/backstage (generic), @backstage/plugin-scaffolder-backend (generic), @backstage/plugin-scaffolder-backend-module-azure (generic), @backstage/plugin-scaffolder-backend-module-bitbucket-cloud (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.4. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps backstage/backstage (generic), @backstage/plugin-scaffolder-backend (generic), @backstage/plugin-scaffolder-backend-module-azure (generic), @backstage/plugin-scaffolder-backend-module-bitbucket-cloud (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| backstage/backstagegeneric | <1.54.6 | 1.54.6 |
| @backstage/plugin-scaffolder-backendgeneric | <4.1.0 | 4.1.0 |
| @backstage/plugin-scaffolder-backend-module-azuregeneric | <0.2.25 | 0.2.25 |
| @backstage/plugin-scaffolder-backend-module-bitbucket-cloudgeneric | <0.3.10 | 0.3.10 |
| @backstage/plugin-scaffolder-backend-module-bitbucket-servergeneric | <0.2.25 | 0.2.25 |
| @backstage/plugin-scaffolder-backend-module-githubgeneric | <0.9.13 | 0.9.13 |
| @backstage/plugin-scaffolder-backend-module-gitlabgeneric | <0.11.10 | 0.11.10 |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user could cause an affected action to fall back to broader integration credentials and perform operations with more access than intended. This issue is fixed in 1.54.6 when operators also enable scaffolder.requireScmUserCredentials after upgrading.
Quoted source text, attributed separately from HOL analysis.