PT-2026-107545 · Backstage · @Backstage/Plugin-Kubernetes-Backend

CVE-2026-106563

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions @backstage/plugin-kubernetes-backend versions prior to 0.21.8
Description Improper entity validation in a deprecated Kubernetes services endpoint allows an authenticated user with Kubernetes read permissions to access workload data beyond their intended scope. By supplying crafted entity data to the endpoint, an attacker can obtain read-only access to Kubernetes object metadata across configured clusters. The affected endpoint is /services/:serviceId.
Recommendations Update @backstage/plugin-kubernetes-backend to version 0.21.8. Disable the deprecated /services/:serviceId route by deploying a custom Kubernetes router that omits it. Restrict access to the kubernetes.resources.read permission to limit the set of users who can reach the endpoint.

Exploit

Fix

Missing Authorization

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-106563
GHSA-R9PH-3637-55PX

Affected Products

@Backstage/Plugin-Kubernetes-Backend