CVE-2026-106487: low-severity vulnerability in backstage
Backstage: Unsupported catalog cluster authentication mode in kubernetes backend
Published
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.5epss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsupported catalog cluster authentication mode in kubernetes backend. Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. With the required endpoint permissions and pod RBAC, the backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. The credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint. This issue is fixed in version 0.21.10.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
Related CVEs — backstage
In the same product, most dangerous first.
CVE-2023-35926HIGHInsecure sandbox in Backstage Scaffolder pluginEPSS 1.9%CVE-2021-41151MEDIUMPath Traversal in @backstage/plugin-scaffolder-backendEPSS 1.3%CVE-2021-32662MEDIUMTechDocs mkdocs.yml path traversalEPSS 1.3%CVE-2021-32660MEDIUMTechDocs content sanitization bypassEPSS 1.3%CVE-2021-43783HIGHPath Traversal in @backstage/plugin-scaffolder-backendEPSS 1.2%CVE-2021-32661MEDIUMTechDocs object element script injectionEPSS 1.2%