{"id":"CVE-2026-106562","title":"Backstage is an open framework for building developer portals","summary":"Backstage is an open framework for building developer portals. Prior to 2.1.6 in @backstage/plugin-search-backend and 1.8.7 in @backstage/plugin-search-backend-module-elasticsearch, search engine permission filtering could return documen…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-754","CWE-863"],"vendor":"backstage","product":"backstage","affected":["backstage < 1.54.1","plugin-search-backend < 2.1.6","plugin-search-backend-module-elasticsearch < 1.8.7"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:16:51.323","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-106562","references":[{"url":"https://github.com/backstage/backstage/commit/2d5d3e77d630455d6d48cfa8f31fd3c126fd6f29","label":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/releases/tag/v1.54.1","label":"security-advisories@github.com"},{"url":"https://github.com/backstage/backstage/security/advisories/GHSA-9325-vq29-gp3v","label":"security-advisories@github.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106562"},{"url":"https://github.com/advisories/GHSA-9325-vq29-gp3v"}],"tags":["nvd","cve.org","ghsa","npm"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T16:14:40.675570Z"},"ingestedAt":"2026-10-07T15:36:04.053Z","aliases":["GHSA-9325-vq29-gp3v"],"ecosystem":"npm","patched":["@backstage/plugin-search-backend 2.1.6","@backstage/plugin-search-backend-module-elasticsearch 1.8.7"],"slug":"CVE-2026-106562","body":"## Overview\n\nBackstage is an open framework for building developer portals. Prior to 2.1.6 in @backstage/plugin-search-backend and 1.8.7 in @backstage/plugin-search-backend-module-elasticsearch, search engine permission filtering could return documents denied by policy. An authenticated Backstage user subject to a DENY policy for search document types could receive unauthorized results in deployments with permission.enabled set to true and an Elasticsearch or OpenSearch backend. This issue is fixed in @backstage/plugin-search-backend 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch 1.8.7.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-106562)\n\nAffected packages:\n\n- `@backstage/plugin-search-backend < 2.1.6`\n- `@backstage/plugin-search-backend-module-elasticsearch < 1.8.7`\n\nPatched in:\n\n- `@backstage/plugin-search-backend 2.1.6`\n- `@backstage/plugin-search-backend-module-elasticsearch 1.8.7`\n\nSource: https://github.com/advisories/GHSA-9325-vq29-gp3v","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}