PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106487 backstage CVE debrief

CVE-2026-106487 debrief based on the supplied source corpus. The CVE record was published on 2026-10-07T18:01:08.000Z and has not been modified since then. This vulnerability affects @backstage/plugin-kubernetes-backend versions prior to 0.21.10, where deployments using catalog cluster discovery may be impacted if catalog contributors can create or modify kubernetes-cluster Resource entities. The backend uses its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. Defenders should verify exposure, especially in deployments using catalog cluster discovery, and take necessary actions to secure their environments.

Vendor
backstage
Product
@backstage/plugin-kubernetes-backend
CVSS
LOW 3.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Backstage deployments using catalog cluster discovery should assess exposure, especially where untrusted users can create or modify Kubernetes cluster Resource entities. They should verify if their deployment is affected and take necessary actions to secure it.

Why it matters

CVE-2026-106487 is a vulnerability in @backstage/plugin-kubernetes-backend that can lead to potential exposure of Kubernetes resources. Defenders should verify exposure, especially in deployments using catalog cluster discovery, and take necessary actions to secure their environments.

  • Potential exposure of Kubernetes resources readable by the backend's local in-cluster identity.
  • Need to verify and restrict catalog ingestion to prevent unauthorized modifications.
  • Requirement to update @backstage/plugin-kubernetes-backend to version 0.21.10 or later.
  • Possible impact on service account authentication configurations.

Technical summary

The @backstage/plugin-kubernetes-backend package prior to version 0.21.10 has a vulnerability in its catalog cluster authentication mode. Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. The backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity.

Defensive priority

Defenders should prioritize verifying exposure in Backstage deployments using catalog cluster discovery, especially where untrusted users can create or modify Kubernetes cluster Resource entities.

Recommended defensive actions

  • Verify if your Backstage deployment uses catalog cluster discovery and if untrusted users can create or modify Kubernetes cluster Resource entities.
  • Restrict catalog ingestion to prevent untrusted users from creating or altering Kubernetes cluster Resource entities.
  • Use the supported static configuration method for service account authentication when required.
  • Update @backstage/plugin-kubernetes-backend to version 0.21.10 or later.
  • Monitor for suspicious activity related to Kubernetes resources readable by the backend's local in-cluster identity.

Evidence notes

The source corpus provides details on the vulnerability in @backstage/plugin-kubernetes-backend versions prior to 0.21.10, where deployments using catalog cluster discovery may be affected if catalog contributors can create or modify kubernetes-cluster Resource entities.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106487 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106487

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106487 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106487

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Backstage: Unsupported catalog cluster authentication mode in kubernetes backend

    Unverified legacy reference

    URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-h53x-hjx6-25gr.json

    osv_dev

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/security/advisories/GHSA-h53x-hjx6-25gr

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/commit/c14f8be6908f0f719b16356e5492352311e28946

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/releases/tag/v1.54.6

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.