CVE-2026-106497: @backstage Plugin-Catalog-Backend

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated user could receive catalog entity data that policy authors intended to restrict. This issue is fixed in version 3.9.1.

Affected products

  • @backstage Plugin-Catalog-Backend: before 3.9.1 (fixed in 3.9.1)
  • Backstage Backstage: before 1.54.6 (fixed in 1.54.6)

Published 2026-10-06. Last modified 2026-10-07.