---
id: CVE-2026-106457
title: Backstage is an open framework for building developer portals
summary: >-
  Backstage is an open framework for building developer portals. From 0.1.0
  until 0.5.0, the
  @backstage/plugin-auth-backend-module-cloudflare-access-provider package is
  affected by insufficient audience validation in the cloudflare access …
severity: medium
cvss: 6.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-287
vendor: backstage
product: backstage
affected:
  - 'backstage >= 1.26.0, < 1.55.0'
  - 'plugin-auth-backend-module-cloudflare-access-provider >= 0.1.0, < 0.5.0'
published: '2026-10-06'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T16:17:38.710'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106457'
references:
  - url: >-
      https://github.com/backstage/backstage/commit/ed9034cacd9def3b3674f0a764fe992f751e204d
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.55.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/security/advisories/GHSA-q333-f498-w2x7
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106457'
  - url: 'https://github.com/advisories/GHSA-q333-f498-w2x7'
tags:
  - nvd
  - cve.org
  - ghsa
  - npm
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-07T15:06:22.900061Z'
ingestedAt: '2026-10-06T21:20:28.980Z'
aliases:
  - GHSA-q333-f498-w2x7
ecosystem: npm
patched:
  - '@backstage/plugin-auth-backend-module-cloudflare-access-provider 0.5.0'
---

## Overview

Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature and team issuer, but affected versions do not verify that the token was issued for the Backstage application. A user holding a valid token for another Access application in the same Cloudflare Zero Trust team may therefore be able to authenticate to Backstage if that token reaches the auth endpoint without the Backstage application's audience already being enforced upstream. Cloudflare Access normally evaluates the protected application before forwarding requests. This issue is fixed in version 0.5.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-106457)

Affected packages:

- `@backstage/plugin-auth-backend-module-cloudflare-access-provider >= 0.1.0, < 0.5.0`

Patched in:

- `@backstage/plugin-auth-backend-module-cloudflare-access-provider 0.5.0`

Source: https://github.com/advisories/GHSA-q333-f498-w2x7
