Apache Airflow Teradata Provider Vulnerability in Compute-Cluster Example Dag
CVE-2026-86843

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
29 September 2026

What is CVE-2026-86843?

The Apache Airflow Teradata provider contains a vulnerability in its compute-cluster example Dag, where all Dag Params were declared as unconstrained free text. This issue allows users with lower trust roles to input SQL fragments that are executed with the privileges of the task's connection, potentially redirecting the task to execute under any connection defined within the deployment. Upgrading to version 3.7.0 or later is recommended, as it constrains parameters to verified identifiers and restricts input to a closed set, thereby preventing unauthorized SQL execution.

Affected Version(s)

Apache Airflow Teradata provider 0 < 3.7.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew Rukin (Arenadata)
Jarek Potiuk
.