Database/Control plane, storage & DevOps
Backstage Kubernetes backend: deprecated services endpoint accepts crafted entity data and widens read scope
Impact
The deprecated Kubernetes services endpoint does not properly validate the entity passed to it, so an authenticated user with Kubernetes read permissions can supply crafted entity data and pull workload data outside the scope they were meant to see. Where a portal is the boundary between teams sharing a GPU cluster, this erases that boundary for workload inventory: who is running what, on which cluster, under which namespace. Exposure is limited to read-only access to Kubernetes object metadata across the configured clusters, with no write path and no credential disclosure claimed in the advisory. Attack complexity is rated high, which fits a flaw that needs the attacker to shape entity input to match targets they cannot enumerate directly.
Who can reach it
Authenticated Backstage user with Kubernetes read permissions, over the network, reaching the plugin's deprecated services endpoint.
What to do
Upgrade @backstage/plugin-kubernetes-backend to 0.21.8 (Backstage release 1.54.1) and restart the Backstage backend. Deployments that do not need the deprecated services endpoint should stop calling it; the advisory does not describe a configuration-only mitigation beyond the upgrade.
References
Related entries
- Grafana: Org Admin can read dashboard permission mappings belonging to other organizationsCVE-2026-11817 · Grafana access-control API (/api/access-control/users/permissions/search), multi-org stacksMedium
- OpenChoreo: autobuild webhook picks its provider from a caller-supplied header and accepts unsigned Bitbucket requestsCVE-2026-73840 · OpenChoreo API (POST /api/v1alpha1/autobuild webhook handler)Medium
- GitLab CE/EE: improper authorization on internal endpoints exposes credentials and tokensCVE-2026-82837 · GitLab CE/EE (internal data emission endpoints, authorization)Medium
- Ansible automation-controller: Bitbucket DC webhook ping skips HMAC check, enumerating webhook-enabled templatesCVE-2026-84717 · Red Hat Ansible Automation Platform automation-controller (Bitbucket Data Center webhook receiver)Medium
- Checkmk REST API: host configuration GET responses return SNMP and IPMI credentials in clear textCVE-2026-92882 · Checkmk REST API (host and folder configuration endpoints)Medium
- DMTF libspdm CSR generation under the mbedTLS crypto backend (cryptlib_mbedtls): Stack corruption inside the firmwareNCVD-2026-006-dmtf-libspdm-csr-generation-unde · DMTF libspdm CSR generation under the mbedTLS crypto backend (cryptlib_mbedtls)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.