4.3
CVE-2026-106562
- EPSS -
- Veröffentlicht 07.10.2026 14:54:13
- Zuletzt bearbeitet 07.10.2026 17:16:51
- Erkennungen
Backstage: Incorrect authorization in search engine permission filtering
Backstage is an open framework for building developer portals. Prior to 2.1.6 in @backstage/plugin-search-backend and 1.8.7 in @backstage/plugin-search-backend-module-elasticsearch, search engine permission filtering could return documents denied by policy. An authenticated Backstage user subject to a DENY policy for search document types could receive unauthorized results in deployments with permission.enabled set to true and an Elasticsearch or OpenSearch backend. This issue is fixed in @backstage/plugin-search-backend 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch 1.8.7.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerbackstage
≫
Produkt
backstage
Version
< 1.54.1
Status
affected
Hersteller@backstage
≫
Produkt
plugin-search-backend
Version
< 2.1.6
Status
affected
Hersteller@backstage
≫
Produkt
plugin-search-backend-module-elasticsearch
Version
< 1.8.7
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-754 Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/backstage/backstage/security/advisories/GHSA-9325-vq29-gp3v
https://github.com/backstage/backstage/commit/2d5d3e77d630455d6d48cfa8f31fd3c126fd6f29
https://github.com/backstage/backstage/releases/tag/v1.54.1