---
id: CVE-2026-106463
title: Backstage is an open framework for building developer portals
summary: >-
  Backstage is an open framework for building developer portals. Prior to 0.8.7,
  the @backstage/plugin-catalog-backend-module-gitlab package is affected by
  improper authorization in gitlab organizational user ingestion. Deployments
  that en…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-863
vendor: backstage
product: backstage
affected:
  - backstage < 1.54.6
  - plugin-catalog-backend-module-gitlab < 0.8.7
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T21:17:17.170'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106463'
references:
  - url: >-
      https://github.com/backstage/backstage/commit/c211b4b67d28efd2f4fac63e35e2ac515e305cb3
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.54.6'
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/security/advisories/GHSA-gp6m-x9vw-5c5x
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T21:20:28.983Z'
---

## Overview

Backstage is an open framework for building developer portals. Prior to 0.8.7, the @backstage/plugin-catalog-backend-module-gitlab package is affected by improper authorization in gitlab organizational user ingestion. Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an access boundary may admit an unintended catalog identity. Depending on sign-in and permission configuration, this may allow unauthorized access with the permissions of a standard authenticated user. This issue is fixed in version 0.8.7.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
