AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106463.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Impact Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an access boundary may admit an unintended catalog identity. Depending on sign-in and permission configuration, this may allow unauthorized access with the permissions of a standard authenticated user. ### Patches - Upgrade `@backstage/plugin-catalog-backend-module-gitlab` to version `0.8.7`. ### Workarounds - Disable event-driven GitLab organization ingestion and rely on scheduled discovery until upgrading. - Enforce organization membership independently at the authenticating proxy or sign-in resolver.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-gp6m-x9vw-5c5x

Open original source · Updated Oct 07, 2026

Backstage has improper authorization in GitLab organizational user ingestion

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
npm@backstage/plugin-catalog-backend-module-gitlab< 0.8.70.8.7

Original records & references

PUBLISHED 2026-10-07T14:01:39-04:00
MODIFIED 2026-10-07T14:01:39-04:00
INGESTED 2026-10-08T12:30:38-04:00