Apache Airflow Teradata Provider Vulnerability in Cloud Storage Credentials
CVE-2026-81862
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 29 September 2026
What is CVE-2026-81862?
Apache Airflow's Teradata provider has a security flaw that exposes cloud storage credentials in SQL statements when using the S3ToTeradataOperator and AzureBlobStorageToTeradataOperator. In scenarios where the source bucket is private and the Teradata authorization is not configured, sensitive credentials are embedded as plain string literals in the SQL statements. These statements are logged and can be accessed by users with permission to view task logs, thus jeopardizing sensitive data. While the recent update to version 3.7.0 helps prevent these credentials from appearing in the Airflow task log, the credentials can still be found in Teradata's DBQL query logs. To mitigate this vulnerability, it is strongly advised to configure the teradata_authorization_name with a Teradata AUTHORIZATION object to prevent credential exposure and to rotate any previously used credentials.
Affected Version(s)
Apache Airflow Teradata provider 0 < 3.7.0