CVE-2026-81862
Last modified
CVE-2026-81862 is a vulnerability of currently unknown severity. Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into the `CREATE MULTISET TABLE ...
Description
Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into the `CREATE MULTISET TABLE ... LOCATION` statement whenever the bucket is private and no `teradata_authorization_name` is configured — which is the default credential path for both operators. The statement is then logged and executed, so the credentials reach two places outside the operator's control. The two operators expose different credentials through different channels, and deployments should check both. `S3ToTeradataOperator` takes its values from `s3_hook.get_credentials()`, which under an instance profile or IRSA returns runtime AWS credentials that were never registered with Airflow's secrets masker — and the STS session token is runtime-generated and therefore unmasked even when an AWS connection is configured. Those credentials appear **in the Airflow task log**, readable by any user with log-view permission on the Dag. `AzureBlobStorageToTeradataOperator` takes its storage account key from the connection, so the masker usually redacts the task-log copy; its exposure is the Teradata side. **Both** operators write the credentials into Teradata's DBQL query logs and live monitoring views, where Airflow's masking never applies and the values persist for that system's log retention period. Affects deployments using either operator against a private bucket or container without a Teradata `AUTHORIZATION` object. Users are advised to upgrade to `apache-airflow-providers-teradata` `3.7.0` or later, which keeps the credential-bearing statement out of the Airflow task log. Upgrading does not remove the credentials from Teradata's query logs and monitoring views, which Airflow cannot redact: users should configure `teradata_authorization_name` with a Teradata `AUTHORIZATION` object so that credentials are never inlined, and should rotate any credentials previously used through the inline path.
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache Airflow Teradata provider | < 3.7.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-81862?
How severe is CVE-2026-81862?
How do I fix CVE-2026-81862?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81852Use of Insufficiently Random Values vulnerability in ash-pro…2.1
- CVE-2026-81853Authorization Bypass Through User-Controlled Key vulnerabili…2.3
- CVE-2026-81855A hardcoded cryptographic client authentication key vulnerab…9.1
- CVE-2026-81859CP4BA - IBM Enterprise Records could allow a local attacker …6.2
- CVE-2026-8186A vulnerability was detected in Open5GS up to 2.7.7. This af…7.5
- CVE-2026-81861CWE-522: Insufficiently Protected Credentials vulnerability …5.9
- CVE-2026-81866Apache NiFi 2.9.0 through 2.11.0 provide Connector configura…4.3
- CVE-2026-81867A Deserialization of Untrusted Data vulnerability in the Jav…9.4
- CVE-2026-81868Steeltoe is an open source project that provides a collectio…6.5
- CVE-2026-81869OpenTelemetry-Go is the Go implementation of OpenTelemetry. …5.1
- CVE-2026-8187A flaw has been found in Open5GS up to 2.7.7. This impacts t…7.5
- CVE-2026-81870OpenTelemetry-Go is the Go implementation of OpenTelemetry. …2
Are you affected by CVE-2026-81862?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
