Apache YuniKorn: flaw bypasses admission control
A notice published on October 7, 2026 describes a flaw in Apache YuniKorn, rated medium severity at CVSS 4.0 4.8, that can bypass user annotation checks.
Source: CVE-2026-97146: Apache YuniKorn permite contornar controle de admissão por falsificação de rótulo do sistema (seclists.org). Text prepared with AI from this source.
What happened and what to do
The security notice, published on October 7, 2026, reports that Apache YuniKorn 1.9.0 and earlier allow user annotation checks to be bypassed when a pod is given the secondary label `app=yunikorn`. In that case, checks limiting annotation content are not run. The stated rating is CVSS 4.0: 4.8, medium severity. Consult the original in the oss-sec mailing list archive, fourth-quarter 2026 issue, item 85, and verify the details and affected version in advisory CVE-2026-97146.
A practical response is to identify clusters and workloads running affected versions, upgrade to a fixed version, and review policies governing pod labels and annotations. A company can also monitor changes to these fields and alert on suspicious combinations, while retaining evidence for audits. The notice excerpt does not specify which fixed version to adopt; confirm that information in the original advisory before planning an upgrade.
How the consultancy can help
Wendelmaques can diagnose cluster exposure, map affected versions and policies, and scope an implementation for upgrades, label and annotation controls, monitoring, and alert operations.
Next step
Send a short description of your YuniKorn environment and exposure questions to receive a scoped proposal.
Consulting for your project
Infrastructure review, deployment and ongoing operations, with scope and pricing defined in the proposal.
Quoted per project
Request a proposal