GHSA-9325-vq29-gp3v: Medium severity npm/@backstage/plugin-search-backend-module-elasticsearch vulnerability

Published Oct 7, 2026
·
Updated

Impact

An authenticated Backstage user subject to a DENY policy for search document types could receive search results they were not authorized to view. This affects deployments with permission.enabled: true and an Elasticsearch or OpenSearch search backend.

Patches

- Upgrade @backstage/plugin-search-backend to 2.1.6 - Upgrade @backstage/plugin-search-backend-module-elasticsearch to 1.8.7

Workarounds

If you are unable to upgrade immediately:

- Temporarily modify permission policies to use CONDITIONAL decisions with per-result filtering rather than blanket DENY for search document types - Restrict Elasticsearch/OpenSearch index access at the cluster level so that the search service account can only reach expected Backstage indices, limiting the blast radius if the authorization bypass is triggered.

Affected Software

2 affected componentsFixes available
npm/@backstage/plugin-search-backend-module-elasticsearch<1.8.7
1.8.7
npm/@backstage/plugin-search-backend<2.1.6
2.1.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@backstage/plugin-search-backend-module-elasticsearch to a version that resolves this vulnerability.

    Fixed in 1.8.7
  2. Upgrade

    Upgrade npm/@backstage/plugin-search-backend to a version that resolves this vulnerability.

    Fixed in 2.1.6
  3. Upgrade

    Upgrade @backstage/plugin-search-backend-module-elasticsearch to a version that resolves this vulnerability.

    Fixed in 1.8.7
  4. Upgrade

    Upgrade @backstage/plugin-search-backend to a version that resolves this vulnerability.

    Fixed in 2.1.6
  5. Configuration

    Temporarily use CONDITIONAL decisions with per-result filtering instead of blanket DENY for search document types.

    Backstage permission policies for search document types permission decision = CONDITIONAL
  6. Compensating control

    Restrict Elasticsearch/OpenSearch index access at the cluster level so the search service account can only reach expected Backstage indices.

Event History

Oct 7, 2026
Advisory Published
via GitHub·06:02 PM
Data Sourced
via GitHub·06:02 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are affected?

Affected deployments have Backstage permissions enabled with permission.enabled: true and use Elasticsearch or OpenSearch as the search backend. The issue specifically concerns users who are subject to a DENY policy for search document types.

2

What access does an attacker need?

An attacker needs to be an authenticated Backstage user. No user interaction is required, but the user must be subject to a DENY policy for the relevant search document types.

3

How can exposure be reduced before upgrading?

Change applicable permission policies from blanket DENY decisions to CONDITIONAL decisions that perform per-result filtering. Also restrict Elasticsearch or OpenSearch cluster access so the search service account can access only the intended Backstage indices.

4

Which package versions contain the fixes?

Upgrade @backstage/plugin-search-backend to version 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch to version 1.8.7.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203