CVE Feed

    Dashboard / CVE / CVE-2026-44374

    CVE-2026-44374

    Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints in @backstage/plugin-catalog-backend-module-unprocessed do not enforce permission authorization checks. Any authenticated user can access unprocessed entity records regardless of ownership. This is an information disclosure vulnerability affecting Backstage installations using this module. This is patched in @backstage/plugin-catalog-backend-module-unprocessed version 0.6.11, @backstage/plugin-catalog-unprocessed-entities-common version 0.0.15 and @backstage/plugin-catalog-unprocessed-entities version 0.2.30.

    Published:May 14, 2026
    Last Modified:Jun 1, 2026
    EPS:May 14, 2026
    EPSS Score:0.00028
    CVSS Score:4.3

    Affected Products

    Vendor
    Backstage
    Product
    Plugin-catalog-backend-module-unprocessed
    Vendor
    Backstage
    Product
    Plugin-catalog-unprocessed-entities
    Vendor
    Backstage
    Product
    Plugin-catalog-unprocessed-entities-common
    Vendor
    Linuxfoundation
    Product
    Backstage\/plugin-catalog-backend-module-unprocessed
    Vendor
    Linuxfoundation
    Product
    Backstage\/plugin-catalog-unprocessed-entities
    Vendor
    Linuxfoundation
    Product
    Backstage\/plugin-catalog-unprocessed-entities-common

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High