PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106456 backstage CVE debrief

CVE-2026-106456 debrief based on CVE Program and NVD records. The @backstage/plugin-proxy-backend package, used in Backstage versions 0.5.0 to 0.6.18, has inconsistent credential enforcement for overlapping proxy routes. This vulnerability allows an unauthenticated caller to potentially reach the nested upstream through Backstage, including with static upstream credentials configured for that proxy. Backstage and plugin-proxy-backend users, administrators, and security teams should assess exposure and verify credential enforcement for overlapping proxy routes in their configurations.

Vendor
backstage
Product
plugin-proxy-backend
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-06
Original CVE updated
2026-10-07
Advisory published
2026-10-06
Advisory updated
2026-10-07

Who should care

Backstage and plugin-proxy-backend users, administrators, and security teams should assess exposure and verify credential enforcement for overlapping proxy routes in their configurations.

Why it matters

CVE-2026-106456 requires attention from Backstage and plugin-proxy-backend users to verify and update their configurations, ensuring proper credential enforcement for overlapping proxy routes to prevent potential unauthorized access and data exposure.

  • Potential unauthorized access to nested proxy routes
  • Possible exposure of sensitive data through static upstream credentials
  • Required verification of credential enforcement for overlapping proxy routes
  • Necessity to update vulnerable versions of plugin-proxy-backend

Technical summary

The @backstage/plugin-proxy-backend package, used in Backstage versions 0.5.0 to 0.6.18, has inconsistent credential enforcement for overlapping proxy routes. An operator can configure overlapping proxy paths with different credential requirements. When a parent path permits unauthenticated access and a nested path requires credentials, the parent exemption can also cover requests handled by the nested proxy. An unauthenticated caller may therefore reach the nested upstream through Backstage, including with static upstream credentials configured for that proxy.

Defensive priority

Medium priority for Backstage and plugin-proxy-backend users

Recommended defensive actions

  • Review and update Backstage and plugin-proxy-backend versions to 0.6.18 or later
  • Verify credential enforcement for overlapping proxy routes in existing configurations
  • Monitor for potential unauthorized access to nested proxy routes
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

Official CVE Program and NVD records detail inconsistent credential enforcement for overlapping proxy routes in Backstage plugin-proxy-backend versions 0.5.0 to 0.6.18. The CVE record was published on 2026-10-06T20:10:41.795Z and has not been modified since then. The vulnerability has a CVSS score of 4.8 and a severity of MEDIUM. The @backstage/plugin-proxy-backend package is affected by this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106456 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106456

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106456 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106456

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Backstage: Inconsistent credential enforcement for overlapping proxy routes

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106456.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/security/advisories/GHSA-472h-9c5j-prrr

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/commit/9df92923ac32558bb80edeceafd8de780c44e218

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/releases/tag/v1.55.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.