Sensitive Information Disclosure in Backstage Kubernetes Plugin
CVE-2026-106561

5MEDIUM

Key Information:

Vendor

Backstage

Vendor
CVE Published:
7 October 2026

What is CVE-2026-106561?

The @backstage/plugin-kubernetes-backend package of Backstage is vulnerable to sensitive information disclosure, allowing authenticated users with standard Kubernetes resource read permissions to access masked sensitive data during Kubernetes resource queries. This vulnerability could potentially expose credentials and other confidential information maintained within connected clusters. Although exposure is confined to resources that are readable by the Backstage service account within specified namespace and label selector criteria, users are urged to upgrade to version 0.21.9 or later for protection against this issue.

Affected Version(s)

backstage < 1.54.2

plugin-kubernetes-backend < 0.21.9

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.