PatchSiren cyber security CVE debrief
CVE-2026-106487 backstage CVE debrief
CVE-2026-106487 debrief based on the supplied source corpus. The CVE record was published on 2026-10-07T18:01:08.000Z and has not been modified since then. This vulnerability affects @backstage/plugin-kubernetes-backend versions prior to 0.21.10, where deployments using catalog cluster discovery may be impacted if catalog contributors can create or modify kubernetes-cluster Resource entities. The backend uses its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. Defenders should verify exposure, especially in deployments using catalog cluster discovery, and take necessary actions to secure their environments.
- Vendor
- backstage
- Product
- @backstage/plugin-kubernetes-backend
- CVSS
- LOW 3.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Backstage deployments using catalog cluster discovery should assess exposure, especially where untrusted users can create or modify Kubernetes cluster Resource entities. They should verify if their deployment is affected and take necessary actions to secure it.
Why it matters
CVE-2026-106487 is a vulnerability in @backstage/plugin-kubernetes-backend that can lead to potential exposure of Kubernetes resources. Defenders should verify exposure, especially in deployments using catalog cluster discovery, and take necessary actions to secure their environments.
- Potential exposure of Kubernetes resources readable by the backend's local in-cluster identity.
- Need to verify and restrict catalog ingestion to prevent unauthorized modifications.
- Requirement to update @backstage/plugin-kubernetes-backend to version 0.21.10 or later.
- Possible impact on service account authentication configurations.
Technical summary
The @backstage/plugin-kubernetes-backend package prior to version 0.21.10 has a vulnerability in its catalog cluster authentication mode. Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. The backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity.
Defensive priority
Defenders should prioritize verifying exposure in Backstage deployments using catalog cluster discovery, especially where untrusted users can create or modify Kubernetes cluster Resource entities.
Recommended defensive actions
- Verify if your Backstage deployment uses catalog cluster discovery and if untrusted users can create or modify Kubernetes cluster Resource entities.
- Restrict catalog ingestion to prevent untrusted users from creating or altering Kubernetes cluster Resource entities.
- Use the supported static configuration method for service account authentication when required.
- Update @backstage/plugin-kubernetes-backend to version 0.21.10 or later.
- Monitor for suspicious activity related to Kubernetes resources readable by the backend's local in-cluster identity.
Evidence notes
The source corpus provides details on the vulnerability in @backstage/plugin-kubernetes-backend versions prior to 0.21.10, where deployments using catalog cluster discovery may be affected if catalog contributors can create or modify kubernetes-cluster Resource entities.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106487 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106487
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106487 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106487
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Backstage: Unsupported catalog cluster authentication mode in kubernetes backend
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-h53x-hjx6-25gr.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/security/advisories/GHSA-h53x-hjx6-25gr
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/commit/c14f8be6908f0f719b16356e5492352311e28946
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/backstage/backstage/releases/tag/v1.54.6
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.