An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. This could allow a restricted service to perform operations beyond its intended scope, including write operations on plugins it was restricted to read-only access for.
Patched in @backstage/backend-defaults version 0.17.8
If you're unable to upgrade immediately:
{
"cwe_ids": [
"CWE-269",
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T17:59:43Z",
"nvd_published_at": "2026-10-06T21:17:18Z",
"severity": "HIGH"
}