Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-86843— Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag

Quick assessment

Affected
Apache Software Foundation Apache Airflow Teradata provider
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache Airflow Teradata 提供商中的计算集群示例 DAG 将所有 DAG 参数均声明为不受约束的自由文本,并直接将这些参数模板化地传入计算集群操作符。这些操作符会将这些值插值到 Teradata DDL 语句中。因此,任何有权触发该 DAG 的用户(其信任级别低于 DAG 作者,且无需拥有自身的 Teradata 凭据)均可提供 SQL 片段,这些片段将以任务运行时的连接身份执行。此外,由于连接 ID 本身也是一个自由文本参数,用户还可以将任务重定向到部署环境中定义的任何其他连接。只有运行此示

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86843

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag
Source: CVE Program / CVE List V5
Vulnerability Description
The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the Dag author, and one that needs no Teradata credentials of its own - could therefore supply SQL fragments that execute under the connection the task runs as, and could additionally redirect the task at any other connection defined in the deployment, because the connection id was itself a free-text Param. Only deployments that run this example Dag, or a Dag copied from it, are affected; the provider's operator code is unchanged. Users of apache-airflow-providers-teradata are recommended to upgrade to version 3.7.0 or later, whose example constrains the Params to validated identifiers and a closed value set and removes connection selection and free-form option strings from trigger-time input. Upgrading does not change a Dag already copied from the example; users who copied it should apply the same constraints to their copy.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Airflow Teradata provider 0 ~ 3.7.0 -

II. Public POCs for CVE-2026-86843

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86843

请登录查看更多情报信息。

Other References for CVE-2026-86843 (2)

Same Patch Batch · Apache Software Foundation · 2026-09-29 · 19 CVEs total

CVE-2026-102496 Apache XMLSchema: Denial of service through deeply nested schema structures
CVE-2026-91012 Apache Karaf: Path Traversal in Config Service Allows Manager-to-Admin Privilege Escalatio
CVE-2026-91048 Apache Karaf: Missing authorization on the jdbc:* shell command scope allows privilege esc
CVE-2026-91085 Apache Karaf: config:install missing ACL entry allows privilege escalation to admin
CVE-2026-92142 Apache Karaf: Authorization bypass in JMX MBean lifecycle operations
CVE-2026-81914 Apache Airflow Google provider: Google Drive query injection via unescaped file and folder
CVE-2026-81862 Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credenti
CVE-2026-81930 Apache Airflow Snowflake provider: Unvalidated account field redirects SQL API bearer toke
CVE-2026-102495 Apache XMLSchema: Denial of service through unbounded recursion when resolving schema impo
CVE-2026-97395 Apache Polaris: Allows authorized table writers to redirect server-side Iceberg FileIO req
CVE-2026-102497 Apache XMLSchema: Denial of service through cyclic schema definitions in the schema walker
CVE-2026-66083 Apache DolphinScheduler: Unauthorized Disclosure of Data Source Information via /datasourc
CVE-2026-82804 Apache DolphinScheduler: Command Injection in the Alert Script Plugin
CVE-2026-81569 Apache DolphinScheduler: Improper Authorization in Sub-Workflow Tasks Allows Unauthorized
CVE-2026-78214 Apache DolphinScheduler: Actuator Endpoint Authentication Bypass via Percent-Encoded Paths
CVE-2026-71899 Apache DolphinScheduler: Missing Authorization in query-dynamic-sub-workflows API Leads to
CVE-2026-71898 Apache DolphinScheduler: Improper Authorization Allows Project Read-Only Users to Execute
CVE-2026-71897 Apache DolphinScheduler: Allows unauthorized workflow operations through batch-copy and ba

IV. Related Vulnerabilities

V. Comments for CVE-2026-86843

No comments yet


Leave a comment