Sensitive Information Disclosure in Backstage Kubernetes Plugin
CVE-2026-106561
5MEDIUM
What is CVE-2026-106561?
The @backstage/plugin-kubernetes-backend package of Backstage is vulnerable to sensitive information disclosure, allowing authenticated users with standard Kubernetes resource read permissions to access masked sensitive data during Kubernetes resource queries. This vulnerability could potentially expose credentials and other confidential information maintained within connected clusters. Although exposure is confined to resources that are readable by the Backstage service account within specified namespace and label selector criteria, users are urged to upgrade to version 0.21.9 or later for protection against this issue.
Affected Version(s)
backstage < 1.54.2
plugin-kubernetes-backend < 0.21.9
