PatchSiren cyber security CVE debrief
CVE-2026-106460 backstage CVE debrief
PatchSiren debrief for CVE-2026-106460: Backstage Explicit negative email verification can be ignored during shared OAuth profile normalization. The vulnerability allows an admitted identity-provider user to assume another catalog identity and obtain its associated access and permissions if the deployment allows an identity-provider user to supply or change an email address without verification. Operators and administrators using Backstage with email-based sign-in resolution must assess exposure and verify configurations.
- Vendor
- backstage
- Product
- @backstage/plugin-auth-node
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Operators and administrators using Backstage with email-based sign-in resolution must assess exposure and verify configurations. This includes reviewing and updating @backstage/plugin-auth-node to the latest version, ensuring that the configured provider restricts sign-in to the intended user population, and supplying an authoritative email address.
Why it matters
CVE-2026-106460 allows an attacker to assume another user's identity and gain access to their permissions if certain conditions are met. Defenders should verify configurations and update vulnerable versions.
- Potential unauthorized access to sensitive information and systems.
- Possible elevation of privileges for malicious users.
- Risk of data breaches or unauthorized modifications.
- Need for verification of email-based sign-in configurations.
Technical summary
The @backstage/plugin-auth-node package is vulnerable to explicit negative email verification being ignored during shared OAuth profile normalization. This can allow an admitted identity-provider user to assume another catalog identity and obtain its associated access and permissions if the deployment allows an identity-provider user to supply or change an email address without verification. Operators using email-based sign-in resolution must ensure that the configured provider restricts sign-in to the intended user population and supplies an authoritative email address.
Defensive priority
Operators using email-based sign-in resolution must ensure that the configured provider restricts sign-in to the intended user population and supplies an authoritative email address.
Recommended defensive actions
- Review and update @backstage/plugin-auth-node to version 0.6.15 or later for installations using npm.
- Review and update @backstage/plugin-auth-node to version 0.7.5 or later for installations using npm version 0.7.0 or later.
- Ensure that the configured provider restricts sign-in to the intended user population and supplies an authoritative email address.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The source corpus provides details on the vulnerability in @backstage/plugin-auth-node, where explicit negative email verification can be ignored during shared OAuth profile normalization. The vulnerability allows an admitted identity-provider user to assume another catalog identity and obtain its associated access and permissions if the deployment allows an identity-provider user to supply or change an email address without verification. Defenders should verify configurations and update vulnerable versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106460 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106460
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106460 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106460
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Backstage: Explicit negative email verification can be ignored during shared OAuth profile norma
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-xm5q-p7w3-x6cp.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/security/advisories/GHSA-xm5q-p7w3-x6cp
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/commit/507e65ab9160aae6b602513dbfaebdd6be0ca8bb
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/commit/f0a43dacd1b501064da042b43eab9c1e06371d38
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/commit/fc5e30aba8ea7282ed3658c3b985cec71051cf9d
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/releases/tag/v1.49.7
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/releases/tag/v1.54.7
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.