AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106462.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Impact Scaffolder actions that interact with source control systems may not consistently enforce the intended credential boundaries under certain configurations. An authenticated user could perform operations with broader access than intended. ### Patches - `@backstage/plugin-scaffolder-backend` version `4.1.0` - `@backstage/plugin-scaffolder-backend-module-azure` version `0.2.25` - `@backstage/plugin-scaffolder-backend-module-bitbucket-cloud` version `0.3.10` - `@backstage/plugin-scaffolder-backend-module-bitbucket-server` version `0.2.25` - `@backstage/plugin-scaffolder-backend-module-github` version `0.9.13` - `@backstage/plugin-scaffolder-backend-module-gitlab` version `0.11.10` The fix introduces a new configuration option that enforces user-provided credentials for supported SCM actions. The new behavior is opt-in for compatibility. After upgrading, set: ```yaml scaffolder: requireScmUserCredentials: true ``` Before enabling this setting, review and update your templates as described in the software templates documentation referred to below. ### Workarounds If you cannot upgrade and enable the setting immediately: - Restrict who can create Scaffolder tasks and which templ

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-29gx-h2m3-xw44

Open original source · Updated Oct 07, 2026

Backstage's scaffolder credential handling may allow unintended GitHub authentication fallback

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
npm@backstage/plugin-scaffolder-backend< 4.1.04.1.0
npm@backstage/plugin-scaffolder-backend-module-github< 0.9.130.9.13
npm@backstage/plugin-scaffolder-backend-module-gitlab< 0.11.100.11.10
npm@backstage/plugin-scaffolder-backend-module-azure< 0.2.250.2.25
npm@backstage/plugin-scaffolder-backend-module-bitbucket-cloud< 0.3.100.3.10
npm@backstage/plugin-scaffolder-backend-module-bitbucket-server< 0.2.250.2.25

Original records & references

PUBLISHED 2026-10-07T14:01:53-04:00
MODIFIED 2026-10-07T14:01:55-04:00
INGESTED 2026-10-08T12:30:38-04:00