« Back to list

Backstage

Backstage Plugin Techdocs Backend: vulnerabilities and CVEs

Backstage Plugin Techdocs Backend has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-106490Medium (6.5)——Oct 6, 2026
Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper input validation in techdocs static content requests. When using the…
CVE-2026-106489Medium (6.5)——Oct 6, 2026
Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper authorization enforcement for techdocs static content. An…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System2
  2. T1210 Exploitation of Remote Services2

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Backstage