Backstage 是一个用于构建开发者门户的开源框架。在 @backstage/plugin-search-backend 版本低于 2.1.6、以及 @backstage/plugin-search-backend-module-elasticsearch 版本低于 1.8.7 的情况下,搜索引擎的权限过滤机制存在缺陷,可能会返回被策略拒绝的文档。在启用了权限控制(permission.enabled 设置为 true)且使用 Elasticsearch 或 OpenSearch 作为后端的部署环境中,若某个已
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| backstage | backstage | < 1.54.1 | - |
|
| @backstage | plugin-search-backend | < 2.1.6 | - |
|
| @backstage | plugin-search-backend-module-elasticsearch | < 1.8.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106558 | 8.8 HIGH | Backstage: Improper validation of TechDocs MkDocs configuration |
| CVE-2026-106510 | 7.7 HIGH | Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml |
| CVE-2026-106556 | 7.7 HIGH | Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization |
| CVE-2026-106560 | 7.1 HIGH | Backstage: Improper repository path validation in a Scaffolder backend module |
| CVE-2026-106559 | 6.3 MEDIUM | Backstage: Improper input validation in Confluence to Markdown scaffolder module |
| CVE-2026-106563 | 5.3 MEDIUM | Backstage: Improper entity validation in deprecated Kubernetes services endpoint |
| CVE-2026-106561 | 5.0 MEDIUM | Backstage: Sensitive information disclosure in Kubernetes resource queries |
No comments yet