GHSA-9325-vq29-gp3vMediumCVSS 4.3

Backstage has incorrect authorization in search engine permission filtering

Published
October 7, 2026
Last Modified
October 7, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

An authenticated Backstage user subject to a DENY policy for search document types could receive search results they were not authorized to view. This affects deployments with permission.enabled: true and an Elasticsearch or OpenSearch search backend.

Patches

  • Upgrade @backstage/plugin-search-backend to 2.1.6
  • Upgrade @backstage/plugin-search-backend-module-elasticsearch to 1.8.7

Workarounds

If you are unable to upgrade immediately:

  • Temporarily modify permission policies to use CONDITIONAL decisions with per-result filtering rather than blanket DENY for search document types
  • Restrict Elasticsearch/OpenSearch index access at the cluster level so that the search service account can only reach expected Backstage indices, limiting the blast radius if the authorization bypass is triggered.

🎯 Affected products2

  • npm/@backstage/plugin-search-backend:< 2.1.6
  • npm/@backstage/plugin-search-backend-module-elasticsearch:< 1.8.7

🔗 References (5)