CVE-2026-86843
Received Received - Intake

SQL Injection in Apache Airflow Teradata Provider

Vulnerability report for CVE-2026-86843, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Apache Software Foundation

Description

The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the Dag author, and one that needs no Teradata credentials of its own - could therefore supply SQL fragments that execute under the connection the task runs as, and could additionally redirect the task at any other connection defined in the deployment, because the connection id was itself a free-text Param. Only deployments that run this example Dag, or a Dag copied from it, are affected; the provider's operator code is unchanged. Users of apache-airflow-providers-teradata are recommended to upgrade to version 3.7.0 or later, whose example constrains the Params to validated identifiers and a closed value set and removes connection selection and free-form option strings from trigger-time input. Upgrading does not change a Dag already copied from the example; users who copied it should apply the same constraints to their copy.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apache airflow_providers_teradata 3.7.0
apache apache_airflow_providers_teradata 3.7.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the Apache Airflow Teradata provider's compute-cluster example DAG. It allows user-supplied parameters to be directly inserted into SQL statements without validation. Since these parameters are templated into Teradata DDL, an attacker with permission to trigger the DAG could inject malicious SQL fragments that execute under the credentials of the task, potentially accessing or modifying data in connected systems.

Detection Guidance

Check for the presence of the Teradata compute-cluster example DAG in your Apache Airflow deployments. Inspect the DAG file for unconstrained parameters that are templated directly into Teradata DDL. Look for parameters that allow free-text input or connection ID selection without validation.

Impact Analysis

If you run the affected example DAG or a copy of it, an attacker with access to trigger the DAG could execute arbitrary SQL commands using the credentials configured for the task. This could lead to data theft, unauthorized modifications, or disruption of services. The impact depends on the permissions of the task's credentials and the sensitivity of the data it can access.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Organizations running affected deployments may face regulatory penalties, reputational damage, and loss of customer trust if data breaches occur due to this issue.

Mitigation Strategies

Upgrade to Apache Airflow Teradata provider version 3.7.0 or later. If you have copied the example DAG, apply the same constraints to your copy by validating parameters and removing free-form input options. Remove user control over connection IDs and other sensitive parameters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86843. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart