CVE-2026-106562: Backstage: Incorrect authorization in search engine permission filtering

Published Oct 7, 2026
·
Updated

Impact

An authenticated Backstage user subject to a DENY policy for search document types could receive search results they were not authorized to view. This affects deployments with permission.enabled: true and an Elasticsearch or OpenSearch search backend.

Patches

- Upgrade @backstage/plugin-search-backend to 2.1.6 - Upgrade @backstage/plugin-search-backend-module-elasticsearch to 1.8.7

Workarounds

If you are unable to upgrade immediately:

- Temporarily modify permission policies to use CONDITIONAL decisions with per-result filtering rather than blanket DENY for search document types - Restrict Elasticsearch/OpenSearch index access at the cluster level so that the search service account can only reach expected Backstage indices, limiting the blast radius if the authorization bypass is triggered.

Other sources

Backstage is an open framework for building developer portals. Prior to 2.1.6 in @backstage/plugin-search-backend and 1.8.7 in @backstage/plugin-search-backend-module-elasticsearch, search engine permission filtering could return documents denied by policy. An authenticated Backstage user subject to a DENY policy for search document types could receive unauthorized results in deployments with permission.enabled set to true and an Elasticsearch or OpenSearch backend. This issue is fixed in @backstage/plugin-search-backend 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch 1.8.7.

— MITRE

Affected Software

4 affected componentsFixes available
npm/@backstage/plugin-search-backend<2.1.6
npm/@backstage/plugin-search-backend-module-elasticsearch<1.8.7
npm/@backstage/plugin-search-backend-module-elasticsearch<1.8.7
1.8.7
npm/@backstage/plugin-search-backend<2.1.6
2.1.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/plugin-search-backend-module-elasticsearch to a version that resolves this vulnerability.

    Fixed in 1.8.7
  2. Upgrade

    Upgrade npm/@backstage/plugin-search-backend to a version that resolves this vulnerability.

    Fixed in 2.1.6
  3. Upgrade

    Upgrade @backstage/plugin-search-backend-module-elasticsearch to a version that resolves this vulnerability.

    Fixed in 1.8.7
  4. Upgrade

    Upgrade @backstage/plugin-search-backend to a version that resolves this vulnerability.

    Fixed in 2.1.6
  5. Configuration

    Temporarily modify permission policies to use CONDITIONAL decisions with per-result filtering rather than blanket DENY for search document types.

    Backstage search permission policies permission decisions for search document types = CONDITIONAL with per-result filtering
  6. Compensating control

    Restrict Elasticsearch/OpenSearch index access at the cluster level so the search service account can only reach expected Backstage indices.

Event History

Oct 7, 2026
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:02 PM
Data Sourced
via GitHub·06:02 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

Affected deployments have permission.enabled set to true and use an Elasticsearch or OpenSearch search backend. The issue applies to @backstage/plugin-search-backend versions before 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch versions before 1.8.7.

2

What does an attacker need to exploit this issue?

An attacker must be an authenticated Backstage user and be subject to a DENY policy for search document types. They can then receive search results containing documents that the policy should deny.

3

Are default deployments affected?

The issue requires permission.enabled to be set to true, so it does not affect deployments unless that permission configuration is enabled. It also requires an Elasticsearch or OpenSearch backend.

4

How can the issue be remediated?

Upgrade @backstage/plugin-search-backend to version 2.1.6 or later and @backstage/plugin-search-backend-module-elasticsearch to version 1.8.7 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203