PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-78243 Apache Software Foundation CVE debrief

Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries. This issue arises when the LDAP server returns a group membership entry with a memberOf attribute for a user specified in the pod, causing the server to crash if the membership record does not start with 'CN='. Users are recommended to upgrade to version 1.10.0, which fixes this issue. The crash occurs due to improper handling of lowercase attribute names, affecting installations with the non-default LDAP group provider configured.

Vendor
Apache Software Foundation
Product
Apache YuniKorn
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders and administrators of Apache YuniKorn installations with LDAP group resolver configured should assess exposure and prioritize upgrading to version 1.10.0. This vulnerability affects operators, platforms, and security teams managing Apache YuniKorn deployments. The impact includes potential crashes and the need for upgrades to prevent exploitation.

Why it matters

Defenders should care about CVE-2026-78243 as it affects Apache YuniKorn installations with LDAP group resolver configured, potentially causing crashes. Upgrading to version 1.10.0 is recommended.

  • Potential crashes due to out of bounds read
  • Need to upgrade to version 1.10.0 for fix
  • Limited information available on exploitation or impact

Technical summary

Apache YuniKorn 1.8.0 and later, if configured with the LDAP group resolver, crashes due to an out of bounds read processing group membership entries. This only affects installations with the non-default LDAP group provider configured. The crash occurs when the LDAP server returns a group membership entry with a memberOf attribute that does not start with 'CN='. The issue is caused by improper handling of lowercase attribute names. Upgrading to version 1.10.0 fixes this issue. Defenders should assess exposure and prioritize upgrading.

Defensive priority

Upgrade to version 1.10.0, assess exposure, and verify remediation

Recommended defensive actions

  • Upgrade Apache YuniKorn to version 1.10.0
  • Assess exposure and verify remediation
  • Monitor for potential crashes
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The CVE record and source item provide details on the vulnerability, but limited information is available on exploitation or impact. The issue is caused by an out-of-bounds read when processing group membership entries with lowercase attribute names. Defenders should verify the affected scope and upgrade to version 1.10.0. The CVE Program record and NIST NVD detail page offer additional information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-78243 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-78243

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-78243 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-78243

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.