PatchSiren cyber security CVE debrief
CVE-2026-106455 backstage CVE debrief
CVE-2026-106455 debrief: Improper validation of MkDocs plugin configuration in TechDocs allows authenticated attackers to cause documentation builds to retrieve and publish data from reachable network locations. Exposure depends on deployment topology, build mode, and target endpoint protections. Upgrade `@backstage/plugin-techdocs-node` to patched versions: `1.14.7` or later for `1.14.x`, `1.15.5` or later for `1.15.x`, and `2.0.0` or later for the mainline.
- Vendor
- backstage
- Product
- @backstage/plugin-techdocs-node
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Backstage deployments, specifically those using TechDocs and MkDocs plugins, should assess exposure based on their deployment topology, build mode, and endpoint protections. They should prioritize upgrading to patched versions of `@backstage/plugin-techdocs-node` and review plugin configurations to prevent unauthorized data retrieval.
Why it matters
CVE-2026-106455 allows authenticated attackers to cause documentation builds to retrieve and publish data from reachable network locations. Defenders should prioritize patching, review plugin configurations, and assess exposure based on deployment topology.
- Potential unauthorized data retrieval from network locations reachable by the build environment
- Need to review and update MkDocs plugin configurations to prevent exploitation
- Priority on upgrading `@backstage/plugin-techdocs-node` to patched versions
- Verification of deployment topology and build mode to assess exposure
Technical summary
CVE-2026-106455 involves improper validation of MkDocs plugin configurations in TechDocs, allowing authenticated attackers with control over a TechDocs source repository to cause documentation builds to retrieve and publish data from network locations reachable by the build environment. The vulnerability's impact depends on the deployment topology, build mode, and protections of target endpoints. Notably, modern cloud metadata services requiring tokens or special headers are not directly accessible through the affected behavior. Patches are available in `@backstage/plugin-techdocs-node` versions `1.14.7`, `1.15.5`, and `2.0.0` or later, which remove MkDocs plugins outside the built-in allowlist. Users can also configure `techdocs.generator.mkdocs.dangerouslyAllowAdditionalPlugins` to retain additional plugins after review.
Defensive priority
Defenders should prioritize upgrading `@backstage/plugin-techdocs-node` to patched versions and review MkDocs plugin configurations to prevent unauthorized data retrieval.
Recommended defensive actions
- Upgrade `@backstage/plugin-techdocs-node` to `1.14.7` or later for `1.14.x` release line
- Upgrade `@backstage/plugin-techdocs-node` to `1.15.5` or later for `1.15.x` release line
- Upgrade `@backstage/plugin-techdocs-node` to `2.0.0` or later for the current mainline
- Review and configure `techdocs.generator.mkdocs.dangerouslyAllowAdditionalPlugins` for additional plugins
- Verify deployment topology and build mode to assess exposure
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The source corpus provides details on the vulnerability and patches but does not specify exploitation or specific victims. Exposure depends on deployment topology and configurations. Defenders should verify configurations, review plugin allowlists, and assess build environment protections to understand potential impact. Additional evidence gathering may be required to confirm affected systems and validate patches.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106455 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106455
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106455 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106455
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Backstage: Improper validation of MkDocs plugin configuration in TechDocs
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-q38j-6vcm-2f5m.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/security/advisories/GHSA-q38j-6vcm-2f5m
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/commit/28aa82ae2815988721dd7bbf43cd69c431dcd71b
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/commit/9f76ea445088961f68c364764cc4b7734f368fc0
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/releases/tag/v1.50.6
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/releases/tag/v1.54.8
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/releases/tag/v1.55.0
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.