GHSA-9325-vq29-gp3vMediumCVSS 4.3
Backstage has incorrect authorization in search engine permission filtering
🔗 CVE IDs covered (1)
📋 Description
Impact
An authenticated Backstage user subject to a DENY policy for search document types could receive search results they were not authorized to view. This affects deployments with permission.enabled: true and an Elasticsearch or OpenSearch search backend.
Patches
- Upgrade
@backstage/plugin-search-backendto 2.1.6 - Upgrade
@backstage/plugin-search-backend-module-elasticsearchto 1.8.7
Workarounds
If you are unable to upgrade immediately:
- Temporarily modify permission policies to use
CONDITIONALdecisions with per-result filtering rather than blanketDENYfor search document types - Restrict Elasticsearch/OpenSearch index access at the cluster level so that the search service account can only reach expected Backstage indices, limiting the blast radius if the authorization bypass is triggered.
🎯 Affected products2
- npm/@backstage/plugin-search-backend:< 2.1.6
- npm/@backstage/plugin-search-backend-module-elasticsearch:< 1.8.7
🔗 References (5)
- https://github.com/backstage/backstage/security/advisories/GHSA-9325-vq29-gp3v
- https://nvd.nist.gov/vuln/detail/CVE-2026-106562
- https://github.com/backstage/backstage/commit/2d5d3e77d630455d6d48cfa8f31fd3c126fd6f29
- https://github.com/backstage/backstage/releases/tag/v1.54.1
- https://github.com/advisories/GHSA-9325-vq29-gp3v