CVE-2026-97146: YuniKorn admission control bypass
An OSS-Sec advisory published on October 7, 2026 describes a way to bypass annotation checks in Apache YuniKorn 1.9.0 and earlier. The reported severity is medium, with a CVSS 4.0 score of 4.8.
Source: CVE-2026-97146: Apache YuniKorn permite contornar controle de admissão por falsificação de rótulo do sistema (seclists.org). Text prepared with AI from this source.
What happened and what to do
The OSS-Sec advisory, published on October 7, 2026, reports CVE-2026-97146 in Apache YuniKorn 1.9.0 and earlier. According to the description, a pod with the secondary label `app=yunikorn` can bypass checks that restrict user annotation content. The reported severity is CVSS 4.0 4.8, medium; exploitation requires elevated privileges and user interaction.
Organizations using these versions can inventory affected clusters and workloads, review pod configuration, and plan an upgrade to a fixed version. They can also monitor pod creation and label or annotation changes, with alerts for combinations that may indicate an attempt to bypass admission controls.
How the consultancy can help
Wendelmaques can assess exposure across clusters and deployment processes, define a remediation scope, and implement upgrades, monitoring, and alerts. Ongoing operation can be scoped to fit the environment.
Next step
Send a short description of your YuniKorn environment and situation. Wendelmaques can assess the scope and prepare an implementation proposal.
Consulting for your project
Infrastructure review, deployment and ongoing operations, with scope and pricing defined in the proposal.
Quoted per project
Request a proposal