CVE-2026-106561: Backstage has a sensitive information disclosure in Kubernetes resource queries
An authenticated user holding the standard Kubernetes resource read permission could retrieve sensitive values that the Kubernetes plugin is designed to mask, potentially exposing credentials and other confidential material held in the connected clusters. Exposure is limited to resources that the Backstage service account is permitted to read and that match the targeted catalog entity’s namespace and label selector. Deployments whose cluster credentials do not grant read access to these resources are unaffected.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-106561 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →