CVE-2026-106506
CVE-2026-106506 is a medium-severity vulnerability with a CVSS 3.x base score of 5.3. The underlying weakness is classified as CWE-202.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-202
- Published:
- Last modified:
Description
Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0.
Frequently asked questions
- What is CVE-2026-106506?
- Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by improper input validation in scaffolder task list ordering. An authenticated Backstage user with permission to create and read relevant scaffolder tasks may be able to infer confidential task data under specific conditions. Successful exploitation requires retained task secrets, visibility of a target task, knowledge of the secret structure, and repeated requests. This issue is fixed in version 4.1.0.
- How severe is CVE-2026-106506?
- CVE-2026-106506 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-106506 being actively exploited?
- It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
- How do I fix CVE-2026-106506?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-106506 published?
- CVE-2026-106506 was published on 2026-10-06.
References
- https://github.com/backstage/backstage/commit/e673a869449874a9169e8f89852e75e862011b93
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/backstage/backstage/security/advisories/GHSA-vwp5-f99x-x3rq
Other CWE-202 vulnerabilities
- CVE-2021-32743 — High (CVSS 8.8): Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and…
- CVE-2024-2088 — High (CVSS 8.5): The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in…
- CVE-2025-25205 — High (CVSS 8.2): Audiobookshelf is a self-hosted audiobook and podcast server. Starting in version 2.17.0 and prior to version 2.19.1, a…
- CVE-2026-33530 — High (CVSS 7.7): InvenTree is an Open Source Inventory Management System. Prior to version 1.2.6, certain API endpoints associated with…
- CVE-2026-30778 — High (CVSS 7.5): The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of…
- CVE-2025-69200 — High (CVSS 7.5): phpMyFAQ is an open source FAQ web application. In versions prior to 4.0.16, an unauthenticated remote attacker can…