When using the Azure Blob Storage provider, an authenticated Backstage user may be able to read restricted TechDocs content when entity-level permissions are enabled. Deployments that intentionally disable the default backend authentication policy may have broader exposure.
Patched in @backstage/plugin-techdocs-backend version 2.2.4
{
"cwe_ids": [
"CWE-22",
"CWE-23"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T18:00:00Z",
"nvd_published_at": "2026-10-06T21:17:17Z",
"severity": "MODERATE"
}