Arbitrary Code Execution Vulnerability in Apache Airflow Kafka Provider
CVE-2026-86792

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
16 September 2026

What is CVE-2026-86792?

The Apache Airflow Kafka provider prior to version 2.0.0 exposes a serious security risk by allowing malicious users to execute arbitrary code through Kafka connection configurations. Specifically, the vulnerability arises from how the provider processes dotted-path strings in the extra field of connections, using import_string without a proper allowlist. This can lead to unauthorized code execution when the Kafka event producer is enabled. Users with basic editing privileges for Airflow connections could potentially compromise the control plane, while those using Google Managed Kafka are safeguarded against this risk. It's recommended to upgrade to version 2.0.0 or later to benefit from enhanced security measures.

Affected Version(s)

Apache Airflow Apache Kafka provider 1.15.0 < 2.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Claude Security Scans
Christos Bisias
.