PT-2026-107543 · Backstage · @Backstage/Plugin-Kubernetes-Backend

CVE-2026-106561

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions @backstage/plugin-kubernetes-backend versions prior to 0.21.9
Description An authenticated user with standard Kubernetes resource read permissions can retrieve sensitive values that the plugin is intended to mask. This may expose credentials and confidential material within connected clusters. The exposure is limited to resources that the Backstage service account is authorized to read and that align with the targeted catalog entity's namespace and label selector.
Recommendations Update @backstage/plugin-kubernetes-backend to version 0.21.9. Enable the permission framework and restrict kubernetes.resources.read to trusted users. Scope the RBAC of the service account used to reach each cluster to prevent it from reading sensitive resource types.

Exploit

Fix

Incorrect Authorization

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106561
GHSA-P795-MQF2-36MF

Affected Products

@Backstage/Plugin-Kubernetes-Backend