AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106457.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Impact The Cloudflare Access auth provider verifies a token's signature and team issuer, but affected versions do not verify that the token was issued for the Backstage application. A user holding a valid token for another Access application in the same Cloudflare Zero Trust team may therefore be able to authenticate to Backstage if that token reaches the auth endpoint without the Backstage application's audience already being enforced upstream. Cloudflare Access normally evaluates the protected application before forwarding requests. The reported reproduction exercises the provider directly and does not demonstrate bypass through the ordinary Cloudflare-protected Backstage URL. Relevant deployment topologies include direct origin access, alternate routes around the intended Access application, or another proxy forwarding the assertion unchanged. A successful sign-in also depends on the deployment's sign-in resolver mapping the presented identity to a Backstage user. The resulting impact depends on the permissions assigned to that identity. ### Patches Upgrade `@backstage/plugin-auth-backend-module-cloudflare-access-provider` to version `0.5.0` or later. The fixed package is av

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-q333-f498-w2x7

Open original source · Updated Oct 07, 2026

Backstage: Insufficient audience validation in the Cloudflare Access auth provider

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
npm@backstage/plugin-auth-backend-module-cloudflare-access-provider>= 0.1.0, < 0.5.00.5.0

Original records & references

PUBLISHED 2026-10-07T16:25:25-04:00
MODIFIED 2026-10-07T16:25:28-04:00
INGESTED 2026-10-08T12:30:39-04:00