Apache YuniKorn Vulnerability Affecting Workload Management
CVE-2026-92393

2LOW

Key Information:

Vendor

Apache

Vendor
CVE Published:
7 October 2026

What is CVE-2026-92393?

The vulnerability in Apache YuniKorn versions 1.9.0 and earlier allows unauthorized users to bypass label and user annotation checks during the workload UPDATE action. This exploitation leads to arbitrary user info annotations being specified, enabling potential alterations to the application ID associated with the workload. As a result, users may gain access to queues they ordinarily wouldn't have, impacting quota utilization and bypassing user-based quota enforcement. Upgrading to version 1.10.0 is highly recommended to mitigate this risk.

Affected Version(s)

Apache YuniKorn 0 < 1.10.0

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

diana.wang.turing@gmail.com
.