Kubernetes Backend Vulnerability in Backstage Affects Cluster Authentication
CVE-2026-106487

3.5LOW

Key Information:

Vendor

Backstage

Vendor
CVE Published:
6 October 2026

What is CVE-2026-106487?

The Kubernetes backend plugin of Backstage prior to version 0.21.10 is susceptible to a vulnerability that allows catalog contributors to create or modify Kubernetes resource entities. If deployments utilize catalog cluster discovery without appropriate safeguards, it could lead to unauthorized access to Kubernetes resources through the backend's local in-cluster identity. This situation could potentially expose sensitive information if the appropriate permissions are in place. It is crucial for users to upgrade to version 0.21.10 to mitigate these risks and enhance the security posture of their applications.

Affected Version(s)

backstage < 1.54.6

plugin-kubernetes-backend < 0.21.10

References

CVSS V3.1

Score:
3.5
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.