CVE-2026-106487Low· 3.5▾ SunlitBackstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsupported catalog cluster authentication mode in kubernetes backend. Deployments using cat…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsupported catalog cluster authentication mode in kubernetes backend. Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. With the required endpoint permissions and pod RBAC, the backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. The credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint. This issue is fixed in version 0.21.10.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106462Medium· 6.4Backstage is an open framework for building developer portals
CVE-2026-106507Medium· 5.3Backstage is an open framework for building developer portals
CVE-2026-106508Medium· 5.3Backstage is an open framework for building developer portals
CVE-2026-106509High· 7.7Backstage is an open framework for building developer portals
CVE-2026-106504Medium· 6.5Backstage is an open framework for building developer portals
CVE-2026-106505High· 7.7Backstage is an open framework for building developer portals