๐Ÿ” CVE Alert

CVE-2026-106562

MEDIUM 4.3

Backstage: Incorrect authorization in search engine permission filtering

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Backstage is an open framework for building developer portals. Prior to 2.1.6 in @backstage/plugin-search-backend and 1.8.7 in @backstage/plugin-search-backend-module-elasticsearch, search engine permission filtering could return documents denied by policy. An authenticated Backstage user subject to a DENY policy for search document types could receive unauthorized results in deployments with permission.enabled set to true and an Elasticsearch or OpenSearch backend. This issue is fixed in @backstage/plugin-search-backend 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch 1.8.7.

CWE CWE-754 CWE-863
Vendor backstage
Product backstage
Published Oct 7, 2026
Last Updated Oct 7, 2026
Stay Ahead of the Next One

Get instant alerts for backstage backstage

Be the first to know when new medium vulnerabilities affecting backstage backstage are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

backstage / backstage
< 1.54.1
@backstage / plugin-search-backend
< 2.1.6
@backstage / plugin-search-backend-module-elasticsearch
< 1.8.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/backstage/backstage/security/advisories/GHSA-9325-vq29-gp3v github.com: https://github.com/backstage/backstage/commit/2d5d3e77d630455d6d48cfa8f31fd3c126fd6f29 github.com: https://github.com/backstage/backstage/releases/tag/v1.54.1