An authenticated Backstage user subject to a DENY policy for search document types could receive search results they were not authorized to view. This affects deployments with permission.enabled: true and an Elasticsearch or OpenSearch search backend.
// patches
Upgrade @backstage/plugin-search-backend to 2.1.6
Upgrade @backstage/plugin-search-backend-module-elasticsearch to 1.8.7
// workarounds
If you are unable to upgrade immediately:
Temporarily modify permission policies to use CONDITIONAL decisions with per-result filtering rather than blanket DENY for search document types
Restrict Elasticsearch/OpenSearch index access at the cluster level so that the search service account can only reach expected Backstage indices, limiting the blast radius if the authorization bypass is triggered.
Checked 2026-10-07 at 23:55 UTC. The most recent advisory here was published 2026-10-07. Updated continuously from NVD, GHSA, OSV and CNA feeds.