CVE-2026-106563 PUBLISHED

Backstage: Improper entity validation in deprecated Kubernetes services endpoint

Assigner: GitHub_M
Reserved: 06.10.2026 Published: 07.10.2026 Updated: 07.10.2026

Backstage is an open framework for building developer portals. Prior to 0.21.8, the @backstage/plugin-kubernetes-backend package is affected by improper entity validation in deprecated kubernetes services endpoint. An authenticated user with Kubernetes read permissions could access Kubernetes workload data beyond their intended scope by supplying crafted entity data to the deprecated services endpoint. The exposure is limited to read-only access to Kubernetes object metadata across configured clusters. This issue is fixed in version 0.21.8.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor backstage
Product backstage
Versions
  • Version < 1.54.1 is affected
Vendor @backstage
Product plugin-kubernetes-backend
Versions
  • Version < 0.21.8 is affected

References

Problem Types

  • CWE-20: Improper Input Validation CWE
  • CWE-862: Missing Authorization CWE