CVE-2026-44374 Details
Description
Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30.
A vulnerability exists in Backstage versions prior to 0.6.11 within the unprocessed entities read endpoints of the '@backstage/plugin-catalog-backend-module-unprocessed' plugin. These endpoints lack proper permission authorization checks, allowing any authenticated user to access unprocessed entity records regardless of ownership. This issue leads to unauthorized information disclosure in Backstage installations using this module.
Users can upgrade to Backstage versions 0.6.11 or later for the '@backstage/plugin-catalog-backend-module-unprocessed' plugin, version 0.2.30 or later for the '@backstage/plugin-catalog-unprocessed-entities' plugin, and version 0.0.15 or later for the '@backstage/plugin-catalog-unprocessed-entities-common' plugin. If an upgrade is not possible, the '@backstage/plugin-catalog-backend-module-unprocessed' module can be removed from the backend until the patch is applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/backstage/backstage/security/advisories/GHSA-p7g9-rp3g-mgfg | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation backstage/plugin-catalog-backend-module-unprocessed | < 0.6.11 |
CPE
Remediation
| |
| linuxfoundation backstage/plugin-catalog-unprocessed-entities | < 0.2.30 |
CPE
Remediation
| |
| linuxfoundation backstage/plugin-catalog-unprocessed-entities-common | < 0.0.15 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | Initial Analysis | [email protected] |
| May 14, 2026 | New CVE Received | [email protected] |