Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-106563— Backstage: Improper entity validation in deprecated Kubernetes services endpoint

Quick assessment

Affected
backstage backstage
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Backstage 是一个用于构建开发者门户的开放框架。在版本 0.21.8 之前,@backstage/plugin-kubernetes-backend 包存在因在已弃用的 Kubernetes 服务端点中对实体进行不当验证而导致的安全问题。具有 Kubernetes 读取权限的已认证用户,可通过向该弃用的服务端点提供精心构造的实体数据,从而访问超出其预期范围的 Kubernetes 工作负载数据。该漏洞的影响仅限于对已配置集群中的 Kubernetes 对象元数据的只读访问。此问题已在版本 0.21.8 中得

CVSS 5.3 · Medium

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-106563

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Backstage: Improper entity validation in deprecated Kubernetes services endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
Backstage is an open framework for building developer portals. Prior to 0.21.8, the @backstage/plugin-kubernetes-backend package is affected by improper entity validation in deprecated kubernetes services endpoint. An authenticated user with Kubernetes read permissions could access Kubernetes workload data beyond their intended scope by supplying crafted entity data to the deprecated services endpoint. The exposure is limited to read-only access to Kubernetes object metadata across configured clusters. This issue is fixed in version 0.21.8.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
backstage backstage < 1.54.1 -
@backstage plugin-kubernetes-backend < 0.21.8 -

II. Public POCs for CVE-2026-106563

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-106563

请登录查看更多情报信息。

Other References for CVE-2026-106563 (3)

Same Patch Batch · backstage · 2026-10-07 · 8 CVEs total

CVE-2026-106558 8.8 HIGH Backstage: Improper validation of TechDocs MkDocs configuration
CVE-2026-106510 7.7 HIGH Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml
CVE-2026-106556 7.7 HIGH Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization
CVE-2026-106560 7.1 HIGH Backstage: Improper repository path validation in a Scaffolder backend module
CVE-2026-106559 6.3 MEDIUM Backstage: Improper input validation in Confluence to Markdown scaffolder module
CVE-2026-106561 5.0 MEDIUM Backstage: Sensitive information disclosure in Kubernetes resource queries
CVE-2026-106562 4.3 MEDIUM Backstage: Incorrect authorization in search engine permission filtering

IV. Related Vulnerabilities

V. Comments for CVE-2026-106563

No comments yet


Leave a comment