CVE-2026-106463: Backstage: Improper authorization in GitLab organizational user ingestion
Backstage is an open framework for building developer portals. Prior to 0.8.7, the @backstage/plugin-catalog-backend-module-gitlab package is affected by improper authorization in gitlab organizational user ingestion. Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an access boundary may admit an unintended catalog identity. Depending on sign-in and permission configuration, this may allow unauthorized access with the permissions of a standard authenticated user. This issue is fixed in version 0.8.7.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@backstage/plugin-catalog-backend-module-gitlabto a version that resolves this vulnerability.Fixed in 0.8.7
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using @backstage/plugin-catalog-backend-module-gitlab before version 0.8.7 are affected if they enable GitLab organization event ingestion and use scoped catalog users as an access boundary.
What access could an unintended catalog identity obtain?
Depending on the deployment's sign-in and permission configuration, an unintended identity may gain the permissions assigned to a standard authenticated user.
What is the remediation?
Upgrade @backstage/plugin-catalog-backend-module-gitlab to version 0.8.7, which fixes the improper authorization issue.