CVE-2026-106487: Backstage: Unsupported catalog cluster authentication mode in kubernetes backend
Impact
Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. With the required endpoint permissions and pod RBAC, the backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. The credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint.
Patches
Patched in @backstage/plugin-kubernetes-backend version 0.21.10
Workarounds
- Do not configure service account authentication through catalog-provided clusters; use the supported static configuration method when service account authentication is required. - Restrict catalog ingestion so untrusted users cannot create or alter Kubernetes cluster Resource entities.
Other sources
Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsupported catalog cluster authentication mode in kubernetes backend. Deployments using catalog cluster discovery may be affected when catalog contributors can create or modify kubernetes-cluster Resource entities. With the required endpoint permissions and pod RBAC, the backend can use its local in-cluster identity, potentially exposing Kubernetes resources readable by that identity. The credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint. This issue is fixed in version 0.21.10.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-kubernetes-backendto a version that resolves this vulnerability.Fixed in 0.21.10 - Upgrade
Upgrade
@backstage/plugin-kubernetes-backendto a version that resolves this vulnerability.Fixed in 0.21.10 - Configuration
Do not configure service account authentication through catalog-provided clusters; use the supported static configuration method when service account authentication is required.
Backstage Kubernetes backend service account authentication configuration source = supported static configuration method - Compensating control
Restrict catalog ingestion so untrusted users cannot create or alter Kubernetes cluster Resource entities, including kubernetes-cluster Resource entities.
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using catalog cluster discovery may be affected if catalog contributors can create or modify kubernetes-cluster Resource entities. Exploitation also requires the relevant endpoint permissions and pod RBAC.
What Kubernetes access could an attacker obtain?
The backend may use its local in-cluster identity to access Kubernetes resources that identity can read. The impact is limited to resources readable by that identity; integrity and availability impact are not indicated.
Are credentials sent to an attacker-controlled cluster endpoint?
No. The local in-cluster credential is used only with the local in-cluster API endpoint and is not sent to the catalog-supplied endpoint.
What version fixes the issue?
Upgrade @backstage/plugin-kubernetes-backend to version 0.21.10 or later. Versions prior to 0.21.10 are affected under the described catalog cluster discovery conditions.