Direct naar de inhoud
⚡ Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 15 min 129 bronnen 1 kritiek 10 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2026-106462

MEDIUM · 6.4 CVSS Gepubliceerd: CWE-441

Beschrijving

Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user could cause an affected action to fall back to broader integration credentials and perform operations with more access than intended. This issue is fixed in 1.54.6 when operators also enable scaffolder.requireScmUserCredentials after upgrading.

References