PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106561 backstage CVE debrief

CVE-2026-106561: Backstage Sensitive Information Disclosure in Kubernetes Resource Queries. The @backstage/plugin-kubernetes-backend package, used in Backstage, is vulnerable to sensitive information disclosure in Kubernetes resource queries. This issue, affecting versions prior to 0.21.9, allows authenticated users with standard Kubernetes resource read permission to retrieve sensitive values designed to be masked. Potential exposure includes credentials and confidential material held in connected clusters. The exposure is limited to resources that the Backstage service account is permitted to read and that match the targeted catalog entity's namespace and label selector. Deploy

Vendor
backstage
Product
plugin-kubernetes-backend
CVSS
MEDIUM 5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Backstage administrators and users with Kubernetes plugin enabled, Kubernetes cluster administrators, Security teams assessing exposure and potential credential compromise, and operators managing affected Backstage deployments. These stakeholders should review and update the plugin, assess exposure, verify permissions, and monitor for credential exposure.

Why it matters

CVE-2026-106561 requires attention from Backstage and Kubernetes administrators to prevent potential sensitive information disclosure and credential exposure. The vulnerability affects plugin-kubernetes-backend versions < 0.21.9 and allows authenticated users with standard Kubernetes resource read permission to retrieve sensitive values. Exposure is limited to resources the Backstage service account can read and match the targeted catalog entity's namespace and label selector. Deployments with cluster credentials not granting read access to these resources are unaffected.

  • Potential exposure of sensitive cluster credentials
  • Possible unauthorized access to confidential material
  • Need for verification of Kubernetes resource read permissions
  • Requirement for updating plugin-kubernetes-backend to version 0.21.9 or later

Technical summary

The @backstage/plugin-kubernetes-backend package, used in Backstage, is affected by sensitive information disclosure in Kubernetes resource queries. An authenticated user with standard Kubernetes resource read permission could retrieve sensitive values designed to be masked, potentially exposing credentials and confidential material in connected clusters. This issue is fixed in version 0.21.9 of the plugin-kubernetes-backend package. The vulnerability is limited to resources the Backstage service account can read and match the targeted catalog entity's namespace and label selector.

Defensive priority

Medium priority for Backstage deployments using Kubernetes plugin

Recommended defensive actions

  • Review and update Backstage plugin-kubernetes-backend to version 0.21.9 or later
  • Assess exposure of sensitive information in connected Kubernetes clusters
  • Verify Kubernetes resource read permissions for Backstage service account
  • Monitor for potential credential exposure in cluster resources
  • Perform compensating controls review for exposed systems
  • Conduct asset inventory of affected Backstage deployments
  • Track exceptions and retest remediated assets

Evidence notes

Official CVE Program record and NVD vulnerability detail page confirm sensitive information disclosure in Kubernetes resource queries for Backstage plugin-kubernetes-backend versions < 0.21.9. Evidence is based on CVE Program and NVD records, with limitations on source-provided details. Defenders should verify Kubernetes resource read permissions, assess exposure of sensitive information, and update plugin-kubernetes-backend to version 0.21.9 or later.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106561 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106561

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106561 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106561

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Backstage: Sensitive information disclosure in Kubernetes resource queries

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106561.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/security/advisories/GHSA-p795-mqf2-36mf

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/commit/388926ae5734bc20bd6a1520d02896be834f6527

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/backstage/backstage/releases/tag/v1.54.2

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.