Apache YuniKorn Vulnerability Affecting Workload Management
CVE-2026-92393
2LOW
What is CVE-2026-92393?
The vulnerability in Apache YuniKorn versions 1.9.0 and earlier allows unauthorized users to bypass label and user annotation checks during the workload UPDATE action. This exploitation leads to arbitrary user info annotations being specified, enabling potential alterations to the application ID associated with the workload. As a result, users may gain access to queues they ordinarily wouldn't have, impacting quota utilization and bypassing user-based quota enforcement. Upgrading to version 1.10.0 is highly recommended to mitigate this risk.
Affected Version(s)
Apache YuniKorn 0 < 1.10.0