PT-2026-107466 · Apache · Apache Yunikorn

·

CVE-2026-92393

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v4.0

2.0

Low

VectorAV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Apache YuniKorn versions prior to 1.10.0
Description An admission control bypass exists during the workload UPDATE action. While the CREATE action correctly enforces checks, the UPDATE action fails to implement label and user annotation checks for Kubernetes objects such as deployments, replicasets, statefulsets, daemonsets, jobs, and cronjobs. This allows a user to specify an arbitrary user info annotation or change the application ID for the workload. By combining these actions, a user could gain access to a queue they are not authorized to use, potentially impacting queue quota usage. Additionally, since user-based quota enforcement relies on the user annotation, user quota tracking can be bypassed even if the application remains in the correct queue.
Recommendations Upgrade to version 1.10.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-92393

Affected Products

Apache Yunikorn