Kubernetes Backend Vulnerability in Backstage Affects Cluster Authentication
CVE-2026-106487
3.5LOW
What is CVE-2026-106487?
The Kubernetes backend plugin of Backstage prior to version 0.21.10 is susceptible to a vulnerability that allows catalog contributors to create or modify Kubernetes resource entities. If deployments utilize catalog cluster discovery without appropriate safeguards, it could lead to unauthorized access to Kubernetes resources through the backend's local in-cluster identity. This situation could potentially expose sensitive information if the appropriate permissions are in place. It is crucial for users to upgrade to version 0.21.10 to mitigate these risks and enhance the security posture of their applications.
Affected Version(s)
backstage < 1.54.6
plugin-kubernetes-backend < 0.21.10
