PatchSiren cyber security CVE debrief
CVE-2026-106456 backstage CVE debrief
CVE-2026-106456 debrief based on CVE Program and NVD records. The @backstage/plugin-proxy-backend package, used in Backstage versions 0.5.0 to 0.6.18, has inconsistent credential enforcement for overlapping proxy routes. This vulnerability allows an unauthenticated caller to potentially reach the nested upstream through Backstage, including with static upstream credentials configured for that proxy. Backstage and plugin-proxy-backend users, administrators, and security teams should assess exposure and verify credential enforcement for overlapping proxy routes in their configurations.
- Vendor
- backstage
- Product
- plugin-proxy-backend
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-06
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-06
- Advisory updated
- 2026-10-07
Who should care
Backstage and plugin-proxy-backend users, administrators, and security teams should assess exposure and verify credential enforcement for overlapping proxy routes in their configurations.
Why it matters
CVE-2026-106456 requires attention from Backstage and plugin-proxy-backend users to verify and update their configurations, ensuring proper credential enforcement for overlapping proxy routes to prevent potential unauthorized access and data exposure.
- Potential unauthorized access to nested proxy routes
- Possible exposure of sensitive data through static upstream credentials
- Required verification of credential enforcement for overlapping proxy routes
- Necessity to update vulnerable versions of plugin-proxy-backend
Technical summary
The @backstage/plugin-proxy-backend package, used in Backstage versions 0.5.0 to 0.6.18, has inconsistent credential enforcement for overlapping proxy routes. An operator can configure overlapping proxy paths with different credential requirements. When a parent path permits unauthenticated access and a nested path requires credentials, the parent exemption can also cover requests handled by the nested proxy. An unauthenticated caller may therefore reach the nested upstream through Backstage, including with static upstream credentials configured for that proxy.
Defensive priority
Medium priority for Backstage and plugin-proxy-backend users
Recommended defensive actions
- Review and update Backstage and plugin-proxy-backend versions to 0.6.18 or later
- Verify credential enforcement for overlapping proxy routes in existing configurations
- Monitor for potential unauthorized access to nested proxy routes
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
Official CVE Program and NVD records detail inconsistent credential enforcement for overlapping proxy routes in Backstage plugin-proxy-backend versions 0.5.0 to 0.6.18. The CVE record was published on 2026-10-06T20:10:41.795Z and has not been modified since then. The vulnerability has a CVSS score of 4.8 and a severity of MEDIUM. The @backstage/plugin-proxy-backend package is affected by this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106456 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106456
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106456 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106456
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Backstage: Inconsistent credential enforcement for overlapping proxy routes
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106456.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/security/advisories/GHSA-472h-9c5j-prrr
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/commit/9df92923ac32558bb80edeceafd8de780c44e218
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/releases/tag/v1.55.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.