CVE-2026-106497: @backstage Plugin-Catalog-Backend
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a confidentiality boundary, an authenticated user could receive catalog entity data that policy authors intended to restrict. This issue is fixed in version 3.9.1.
Affected products
- @backstage Plugin-Catalog-Backend: before 3.9.1 (fixed in 3.9.1)
- Backstage Backstage: before 1.54.6 (fixed in 1.54.6)
Published 2026-10-06. Last modified 2026-10-07.