CVE-2026-106563: Backstage: Improper entity validation in deprecated Kubernetes services endpoint
Impact
An authenticated user with Kubernetes read permissions could access Kubernetes workload data beyond their intended scope by supplying crafted entity data to the deprecated services endpoint. The exposure is limited to read-only access to Kubernetes object metadata across configured clusters.
Patches
Patched in @backstage/plugin-kubernetes-backend version 0.21.8.
Workarounds
- Disable the deprecated /services/:serviceId route by deploying a custom Kubernetes router that omits it. - Restrict access to the kubernetes.resources.read permission to limit the set of users who can reach the endpoint.
Other sources
Backstage is an open framework for building developer portals. Prior to 0.21.8, the @backstage/plugin-kubernetes-backend package is affected by improper entity validation in deprecated kubernetes services endpoint. An authenticated user with Kubernetes read permissions could access Kubernetes workload data beyond their intended scope by supplying crafted entity data to the deprecated services endpoint. The exposure is limited to read-only access to Kubernetes object metadata across configured clusters. This issue is fixed in version 0.21.8.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-kubernetes-backendto a version that resolves this vulnerability.Fixed in 0.21.8 - Upgrade
Upgrade
@backstage/plugin-kubernetes-backendto a version that resolves this vulnerability.Fixed in 0.21.8 - Configuration
Deploy a custom Kubernetes router that omits the deprecated /services/:serviceId route.
Backstage Kubernetes router /services/:serviceId route = disabled - Configuration
Restrict access to the kubernetes.resources.read permission to limit which users can reach the endpoint.
Backstage Kubernetes permissions kubernetes.resources.read = restricted
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be an authenticated user and have Kubernetes read permissions. They would also need to send crafted entity data to the deprecated Kubernetes services endpoint.
What information could be exposed?
The exposure is limited to read-only access to Kubernetes object metadata across configured clusters. The issue does not provide integrity or availability impact in the supplied severity vector.
Are deployments using the affected package version exposed by default?
Exposure depends on use of the deprecated Kubernetes services endpoint and on users having Kubernetes read permissions. The provided data does not establish that every default deployment enables or uses that endpoint.
What version fixes the issue?
Upgrade @backstage/plugin-kubernetes-backend to version 0.21.8 or later. Versions prior to 0.21.8 are affected.