CVE-2026-106497Medium· 4.3▾ SunlitBackstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated user could receive catalog entity data that policy authors intended to restrict. This issue is fixed in version 3.9.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106503High· 8.1Backstage is an open framework for building developer portals
CVE-2026-106498High· 7.7Backstage is an open framework for building developer portals
CVE-2026-106496Low· 3.1Backstage is an open framework for building developer portals
CVE-2026-106492High· 7.6Backstage is an open framework for building developer portals
CVE-2026-106463Medium· 5.4Backstage is an open framework for building developer portals
CVE-2026-106461Medium· 4.3Backstage is an open framework for building developer portals