Arbitrary Code Execution Vulnerability in Apache Airflow Kafka Provider
CVE-2026-86792
Key Information:
- Vendor
Apache
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-86792?
The Apache Airflow Kafka provider prior to version 2.0.0 exposes a serious security risk by allowing malicious users to execute arbitrary code through Kafka connection configurations. Specifically, the vulnerability arises from how the provider processes dotted-path strings in the extra field of connections, using import_string without a proper allowlist. This can lead to unauthorized code execution when the Kafka event producer is enabled. Users with basic editing privileges for Airflow connections could potentially compromise the control plane, while those using Google Managed Kafka are safeguarded against this risk. It's recommended to upgrade to version 2.0.0 or later to benefit from enhanced security measures.
Affected Version(s)
Apache Airflow Apache Kafka provider 1.15.0 < 2.0.0