PT-2026-107468 · Apache · Apache Yunikorn

·

CVE-2026-97146

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Apache YuniKorn versions prior to 1.10.0
Description An admission control bypass exists where the check for user annotation is skipped if a pod is configured with a secondary label app=yunikorn. This label is intended to identify the YuniKorn application within deployments. By forging this label, any user can specify an arbitrary user info annotation, potentially gaining access to queues they are not authorized to use. This can lead to incorrect quota usage or allow users to bypass user-based quota enforcement, even when running in the correct queue.
Recommendations Upgrade to version 1.10.0.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97146

Affected Products

Apache Yunikorn