Search Engine Permission Flaw in Backstage by Spotify
CVE-2026-106562
4.3MEDIUM
What is CVE-2026-106562?
The Backstage framework from Spotify encountered a significant issue where its search engine permission filtering did not properly enforce policies. This flaw allowed authenticated users, even those subject to a DENY policy for certain search document types, to access unauthorized search results. This vulnerability arises in deployments using a permission-enabled configuration with either Elasticsearch or OpenSearch as a backend, potentially exposing sensitive information. Versions @backstage/plugin-search-backend 2.1.6 and @backstage/plugin-search-backend-module-elasticsearch 1.8.7 and higher have implemented fixes to remediate this issue.
Affected Version(s)
backstage < 1.54.1
plugin-search-backend < 2.1.6
plugin-search-backend-module-elasticsearch < 1.8.7
