CVE-2026-106487: @backstage Plugin-Kubernetes-Backend

Low severity, CVSS 3.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsupported catalog cluster authentication mode in kubernetes backend. Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. With the required endpoint permissions and pod RBAC, the backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. The credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint. This issue is fixed in version 0.21.10.

Affected products

  • @backstage Plugin-Kubernetes-Backend: before 0.21.10 (fixed in 0.21.10)
  • Backstage Backstage: before 1.54.6 (fixed in 1.54.6)

Published 2026-10-06. Last modified 2026-10-09.