Advisory CVE-2026-92393 describes a flaw in Apache YuniKorn, a workload scheduler for Kubernetes. According to the source, in YuniKorn 1.9.0 and earlier versions, the workload UPDATE operation does not implement checks on user labels and annotations, which allows all of those checks to be bypassed. The source lists affected versions as those before 1.10.0. The CVSS 4.0 score is 2.0 (low), with vector AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Per the vector, exploitation requires network access, high privileges and user interaction, and the impact is rated low for integrity and none for confidentiality and availability.
The source lists Kubernetes objects such as deployments and replicasets as YuniKorn workloads, and the text received is cut off after that list. To assess reach in your environment, check the full list in the original advisory. The text here is an automatic translation of the feed, so technical details should be verified against the primary source before any decision.
The relevance for an organization lies in execution infrastructure, not in AI use itself. If your team runs YuniKorn to schedule workloads, including AI workloads, label and annotation policies could be ignored by anyone with update permission. Rota Nacional does not run or patch YuniKorn, and this bulletin does not describe any platform capability that solves the engineering problem.