CVE-2026-106562: Backstage: Incorrect authorization in search engine permission filtering
Impact
An authenticated Backstage user subject to a DENY policy for search document types could receive search results they were not authorized to view. This affects deployments with permission.enabled: true and an Elasticsearch or OpenSearch search backend.
Patches
- Upgrade @backstage/plugin-search-backend to 2.1.6 - Upgrade @backstage/plugin-search-backend-module-elasticsearch to 1.8.7
Workarounds
If you are unable to upgrade immediately:
- Temporarily modify permission policies to use CONDITIONAL decisions with per-result filtering rather than blanket DENY for search document types - Restrict Elasticsearch/OpenSearch index access at the cluster level so that the search service account can only reach expected Backstage indices, limiting the blast radius if the authorization bypass is triggered.
Other sources
Backstage is an open framework for building developer portals. Prior to 2.1.6 in @backstage/plugin-search-backend and 1.8.7 in @backstage/plugin-search-backend-module-elasticsearch, search engine permission filtering could return documents denied by policy. An authenticated Backstage user subject to a DENY policy for search document types could receive unauthorized results in deployments with permission.enabled set to true and an Elasticsearch or OpenSearch backend. This issue is fixed in @backstage/plugin-search-backend 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch 1.8.7.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-search-backend-module-elasticsearchto a version that resolves this vulnerability.Fixed in 1.8.7 - Upgrade
Upgrade
npm/@backstage/plugin-search-backendto a version that resolves this vulnerability.Fixed in 2.1.6 - Upgrade
Upgrade
@backstage/plugin-search-backend-module-elasticsearchto a version that resolves this vulnerability.Fixed in 1.8.7 - Upgrade
Upgrade
@backstage/plugin-search-backendto a version that resolves this vulnerability.Fixed in 2.1.6 - Configuration
Temporarily modify permission policies to use CONDITIONAL decisions with per-result filtering rather than blanket DENY for search document types.
Backstage search permission policies permission decisions for search document types = CONDITIONAL with per-result filtering - Compensating control
Restrict Elasticsearch/OpenSearch index access at the cluster level so the search service account can only reach expected Backstage indices.
Event History
Frequently Asked Questions
Which deployments are affected?
Affected deployments have permission.enabled set to true and use an Elasticsearch or OpenSearch search backend. The issue applies to @backstage/plugin-search-backend versions before 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch versions before 1.8.7.
What does an attacker need to exploit this issue?
An attacker must be an authenticated Backstage user and be subject to a DENY policy for search document types. They can then receive search results containing documents that the policy should deny.
Are default deployments affected?
The issue requires permission.enabled to be set to true, so it does not affect deployments unless that permission configuration is enabled. It also requires an Elasticsearch or OpenSearch backend.
How can the issue be remediated?
Upgrade @backstage/plugin-search-backend to version 2.1.6 or later and @backstage/plugin-search-backend-module-elasticsearch to version 1.8.7 or later.