Apache Airflow Teradata Provider Vulnerability in Cloud Storage Credentials
CVE-2026-81862

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-81862?

Apache Airflow's Teradata provider has a security flaw that exposes cloud storage credentials in SQL statements when using the S3ToTeradataOperator and AzureBlobStorageToTeradataOperator. In scenarios where the source bucket is private and the Teradata authorization is not configured, sensitive credentials are embedded as plain string literals in the SQL statements. These statements are logged and can be accessed by users with permission to view task logs, thus jeopardizing sensitive data. While the recent update to version 3.7.0 helps prevent these credentials from appearing in the Airflow task log, the credentials can still be found in Teradata's DBQL query logs. To mitigate this vulnerability, it is strongly advised to configure the teradata_authorization_name with a Teradata AUTHORIZATION object to prevent credential exposure and to rotate any previously used credentials.

Affected Version(s)

Apache Airflow Teradata provider 0 < 3.7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude Security Scans
Jarek Potiuk
.