Skip to content
Rota Nacional

Cyber ·

CVE-2026-97146: Apache YuniKorn allows bypassing admission control through a forged system label

Security advisory on Apache YuniKorn 1.9.0 and earlier: a secondary label set on a pod disables checks on user annotation content. Fixed in version 1.10.0. Medium severity (CVSS 4.0: 4.8).

Source: advisory published on 7 October 2026 in the oss-sec feed, with an automatic translation of the original content and authorship credited to Wilfred Spiegelenburg in the source itself. Identifier: CVE-2026-97146. Product: Apache YuniKorn, a resource scheduler used in Kubernetes clusters. Affected versions: earlier than 1.10.0, including 1.9.0 and earlier. Severity: CVSS 4.0 score 4.8, rated medium, with a vector indicating network access, high privileges required, user interaction required, no confidentiality or availability impact and low integrity impact. Description: when a specific secondary label is set on a pod, checks that limit the content of the user annotation are not run. When the pod carries the label 'app=yunikorn', those checks are skipped. The available excerpt is cut off in the explanation of how the label identifies the component, so the full details should be read in the original. Relevance: operators of YuniKorn should upgrade to 1.10.0 or later and review who can create pods with labels and annotations. Limit: Rota Nacional does not run this scheduler and does not fix the flaw, since the advisory concerns third-party infrastructure.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.

Try free