PT-2026-107543 · Backstage · @Backstage/Plugin-Kubernetes-Backend
CVE-2026-106561
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v3.1
5.0
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
@backstage/plugin-kubernetes-backend versions prior to 0.21.9
Description
An authenticated user with standard Kubernetes resource read permissions can retrieve sensitive values that the plugin is intended to mask. This may expose credentials and confidential material within connected clusters. The exposure is limited to resources that the Backstage service account is authorized to read and that align with the targeted catalog entity's namespace and label selector.
Recommendations
Update @backstage/plugin-kubernetes-backend to version 0.21.9.
Enable the permission framework and restrict
kubernetes.resources.read to trusted users.
Scope the RBAC of the service account used to reach each cluster to prevent it from reading sensitive resource types.Exploit
Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Backstage/Plugin-Kubernetes-Backend