PT-2026-107545 · Backstage · @Backstage/Plugin-Kubernetes-Backend
CVE-2026-106563
·
Published
2026-10-07
·
Updated
2026-10-07
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
@backstage/plugin-kubernetes-backend versions prior to 0.21.8
Description
Improper entity validation in a deprecated Kubernetes services endpoint allows an authenticated user with Kubernetes read permissions to access workload data beyond their intended scope. By supplying crafted entity data to the endpoint, an attacker can obtain read-only access to Kubernetes object metadata across configured clusters. The affected endpoint is
/services/:serviceId.Recommendations
Update @backstage/plugin-kubernetes-backend to version 0.21.8.
Disable the deprecated
/services/:serviceId route by deploying a custom Kubernetes router that omits it.
Restrict access to the kubernetes.resources.read permission to limit the set of users who can reach the endpoint.Exploit
Fix
Missing Authorization
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Backstage/Plugin-Kubernetes-Backend