{"id":"GHSA-9325-vq29-gp3v","summary":"Backstage has incorrect authorization in search engine permission filtering","details":"### Impact\n\nAn authenticated Backstage user subject to a `DENY` policy for search document types could receive search results they were not authorized to view. This affects deployments with `permission.enabled: true` and an Elasticsearch or OpenSearch search backend.\n\n### Patches\n\n- Upgrade `@backstage/plugin-search-backend` to 2.1.6\n- Upgrade `@backstage/plugin-search-backend-module-elasticsearch` to 1.8.7\n\n### Workarounds\n\nIf you are unable to upgrade immediately:\n\n- Temporarily modify permission policies to use `CONDITIONAL` decisions with per-result filtering rather than blanket `DENY` for search document types\n- Restrict Elasticsearch/OpenSearch index access at the cluster level so that the search service account can only reach expected Backstage indices, limiting the blast radius if the authorization bypass is triggered.","aliases":["CVE-2026-106562"],"modified":"2026-10-07T18:15:11.183397966Z","published":"2026-10-07T18:02:52Z","database_specific":{"nvd_published_at":"2026-10-07T15:17:17Z","cwe_ids":["CWE-754","CWE-863"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-07T18:02:52Z"},"references":[{"type":"WEB","url":"https://github.com/backstage/backstage/security/advisories/GHSA-9325-vq29-gp3v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-106562"},{"type":"WEB","url":"https://github.com/backstage/backstage/commit/2d5d3e77d630455d6d48cfa8f31fd3c126fd6f29"},{"type":"PACKAGE","url":"https://github.com/backstage/backstage"},{"type":"WEB","url":"https://github.com/backstage/backstage/releases/tag/v1.54.1"}],"affected":[{"package":{"name":"@backstage/plugin-search-backend","ecosystem":"npm","purl":"pkg:npm/%40backstage/plugin-search-backend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.1.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9325-vq29-gp3v/GHSA-9325-vq29-gp3v.json"}},{"package":{"name":"@backstage/plugin-search-backend-module-elasticsearch","ecosystem":"npm","purl":"pkg:npm/%40backstage/plugin-search-backend-module-elasticsearch"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.8.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-9325-vq29-gp3v/GHSA-9325-vq29-gp3v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}