CVE-2026-106489Medium· 6.5▾ SunlitBackstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper authorization enforcement for techdocs static content. An authenticated user with acces…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper authorization enforcement for techdocs static content. An authenticated user with access to one TechDocs documentation site could craft a URL able to read documentation belonging to a different entity. This only affects deployments using the external TechDocs builder with an external storage provider (S3, GCS, etc.) and the permission framework enabled. Instances that do not use the permission framework are unaffected, since TechDocs content is visible to all authenticated users by design. This issue is fixed in version 2.2.4.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106508Medium· 5.3Backstage is an open framework for building developer portals
CVE-2026-106496Low· 3.1Backstage is an open framework for building developer portals
CVE-2026-106494Medium· 4.4Backstage is an open framework for building developer portals
CVE-2026-106491Medium· 6.4Backstage is an open framework for building developer portals
CVE-2026-106493Low· 3.0Backstage is an open framework for building developer portals
CVE-2026-106490Medium· 6.5Backstage is an open framework for building developer portals