Skip to content

Apache YuniKorn: admission check bypass

An advisory published on October 7, 2026, reports that Apache YuniKorn 1.9.0 and earlier do not check user labels and annotations for workload UPDATE operations, allowing admission controls to be bypassed. The reported severity is low (CVSS 4.0: 2.0).

By Wendelmaques ·

Source: CVE-2026-92393: Apache YuniKorn permite contornar controle de admissão com operação UPDATE de workload (seclists.org). Text prepared with AI from this source.

What happened and what to do

The Apache YuniKorn advisory says versions before 1.10.0, including 1.9.0, do not apply user-label and annotation checks to workload UPDATE operations. This can bypass admission checks. The reported severity is low: CVSS 4.0: 2.0. The report was published on October 7, 2026.

A company can inventory cluster versions and workloads, prioritize upgrading to version 1.10.0 or later, and validate admission rules for UPDATE operations in a controlled environment. It can also monitor workload changes and record denied attempts to detect deviations and guide operational response.

How the consultancy can help

Wendelmaques can assess cluster exposure, define a scoped upgrade and admission-rule validation, and implement monitoring and operational procedures for tracking workload changes.

Next step

Send a short description of your YuniKorn environment and upgrade process to receive a scoped proposal.

Consulting for your project

Infrastructure review, deployment and ongoing operations, with scope and pricing defined in the proposal.

Quoted per project

Request a proposal

Looking for something else?Frequently asked questionsArticlesContact