Disclosure summary
### Impact The Cloudflare Access auth provider verifies a token's signature and team issuer, but affected versions do not verify that the token was issued for the Backstage application. A user holding a valid token for another Access application in the same Cloudflare Zero Trust team may therefore be able to authenticate to Backstage if that token reaches the auth endpoint without the Backstage application's audience already being enforced upstream. Cloudflare Access normally evaluates the protected application before forwarding requests. The reported reproduction exercises the provider directly and does not demonstrate bypass through the ordinary Cloudflare-protected Backstage URL. Relevant deployment topologies include direct origin access, alternate routes around the intended Access application, or another proxy forwarding the assertion unchanged. A successful sign-in also depends on the deployment's sign-in resolver mapping the presented identity to a Backstage user. The resulting impact depends on the permissions assigned to that identity. ### Patches Upgrade `@backstage/plugin-auth-backend-module-cloudflare-access-provider` to version `0.5.0` or later. The fixed package is av
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-q333-f498-w2x7
Open original source · Updated Oct 07, 2026
Backstage: Insufficient audience validation in the Cloudflare Access auth provider
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @backstage/plugin-auth-backend-module-cloudflare-access-provider | >= 0.1.0, < 0.5.0 | 0.5.0 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T16:25:25-04:00
MODIFIED 2026-10-07T16:25:28-04:00
INGESTED 2026-10-08T12:30:39-04:00