Deployments that enable GitLab organization event ingestion and rely on scoped catalog users as an access boundary may admit an unintended catalog identity. Depending on sign-in and permission configuration, this may allow unauthorized access with the permissions of a standard authenticated user.
@backstage/plugin-catalog-backend-module-gitlab to version 0.8.7.{
"cwe_ids": [
"CWE-863"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T18:01:39Z",
"nvd_published_at": "2026-10-06T21:17:17Z",
"severity": "MODERATE"
}