CVE-2026-106457Medium· 6.8▾ SunlitBackstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature and team issuer, but affected versions do not verify that the token was issued for the Backstage application. A user holding a valid token for another Access application in the same Cloudflare Zero Trust team may therefore be able to authenticate to Backstage if that token reaches the auth endpoint without the Backstage application's audience already being enforced upstream. Cloudflare Access normally evaluates the protected application before forwarding requests. This issue is fixed in version 0.5.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106488High· 8.1Backstage is an open framework for building developer portals
CVE-2026-106460Medium· 6.8Backstage is an open framework for building developer portals
CVE-2026-106458Medium· 6.5Backstage is an open framework for building developer portals
CVE-2026-106459High· 8.5Backstage is an open framework for building developer portals
CVE-2026-106455High· 7.7Backstage is an open framework for building developer portals
CVE-2026-106456Medium· 4.8Backstage is an open framework for building developer portals