Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mopmonk-Ai@Tophant.Com

#53857of 57,597
4.8Total CVSS
Vulnerabilities · 1
PT-2026-107468
4.8
2026-10-07
Apache · Apache Yunikorn · CVE-2026-97146
**Name of the Vulnerable Software and Affected Versions** Apache YuniKorn versions prior to 1.10.0 **Description** An admission control bypass exists where the check for user annotation is skipped if a pod is configured with a secondary label `app=yunikorn`. This label is intended to identify the YuniKorn application within deployments. By forging this label, any user can specify an arbitrary user info annotation, potentially gaining access to queues they are not authorized to use. This can lead to incorrect quota usage or allow users to bypass user-based quota enforcement, even when running in the correct queue. **Recommendations** Upgrade to version 1.10.0.