CVE-2026-106562
Awaiting Analysis Awaiting Analysis - Queue

Permission Filter Bypass in Backstage Search Backend

Vulnerability report for CVE-2026-106562, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: GitHub, Inc.

Description

Backstage is an open framework for building developer portals. Prior to 2.1.6 in @backstage/plugin-search-backend and 1.8.7 in @backstage/plugin-search-backend-module-elasticsearch, search engine permission filtering could return documents denied by policy. An authenticated Backstage user subject to a DENY policy for search document types could receive unauthorized results in deployments with permission.enabled set to true and an Elasticsearch or OpenSearch backend. This issue is fixed in @backstage/plugin-search-backend 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch 1.8.7.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
backstage backstage < 1.54.1
@backstage plugin-search-backend < 2.1.6
@backstage plugin-search-backend-module-elasticsearch < 1.8.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-754 The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Backstage allows an authenticated user with a DENY policy for search document types to receive unauthorized search results. It affects deployments using Elasticsearch or OpenSearch with permission.enabled set to true. The issue occurs in versions of @backstage/plugin-search-backend before 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch before 1.8.7 due to incorrect authorization in search engine permission filtering.

Detection Guidance

Check Backstage plugin versions for @backstage/plugin-search-backend (< 2.1.6) and @backstage/plugin-search-backend-module-elasticsearch (< 1.8.7). Verify if permission.enabled is set to true in deployments using Elasticsearch or OpenSearch.

Impact Analysis

An attacker could access sensitive information they are not authorized to see by exploiting this flaw. This could lead to data leaks, unauthorized access to documents, or compliance violations depending on the exposed data. The attack requires authentication but has low complexity once access is gained.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) by exposing personal or protected health information. Organizations using Backstage with Elasticsearch/OpenSearch may face compliance risks if unauthorized data access occurs.

Mitigation Strategies
  • Upgrade @backstage/plugin-search-backend to version 2.1.6 or later.
  • Upgrade @backstage/plugin-search-backend-module-elasticsearch to version 1.8.7 or later.
  • Modify permission policies to use CONDITIONAL decisions as a temporary workaround.
  • Restrict Elasticsearch/OpenSearch index access at the cluster level.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-106562. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart