CVE-2026-81914
Last modified
CVE-2026-81914 is a vulnerability of currently unknown severity. Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the query. The names are frequently not written by the Dag author.
Description
Apache Airflow's Google provider built Google Drive search expressions by interpolating file and folder names directly into single-quoted string literals, without escaping the quote character that delimits them. A name containing an apostrophe therefore terminated the literal early and appended clauses of the attacker's choosing to the query. The names are frequently not written by the Dag author. In a wildcard `gcs_to_gdrive` transfer they come from the source bucket listing, so anyone able to create objects in that bucket controls them — typically an external data producer or an ingest-only service account, a different trust principal from the Dag author. An injected clause can broaden the match and so steer which file or folder the hook resolves: an upload can be directed into a folder the attacker named, and, because downloads select the most recently modified match, a download can return a file they placed rather than the one the Dag asked for. Affects deployments passing externally-sourced names to the Google Drive hook, including wildcard `gcs_to_gdrive` transfers from buckets writable by less-trusted principals. Users are advised to upgrade to `apache-airflow-providers-google` `22.6.0` or later, which escapes quote and backslash characters in every value interpolated into a Drive query.
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache Airflow Google provider | < 22.6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-81914?
How severe is CVE-2026-81914?
How do I fix CVE-2026-81914?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-81909Concrete CMS 9 through 9.5.2 is vulnerable to Missing Author…5.9
- CVE-2026-8191A vulnerability was identified in Wavlink NU516U1 M16U1_V240…8.8
- CVE-2026-81910Concrete CMS 9 through 9.5.2 is vulnerable to Server-Side Te…6.5
- CVE-2026-81911Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored…5.4
- CVE-2026-81912Concrete CMS before 9.5.3 is vulnerable to Cross-Site Reques…5.7
- CVE-2026-81913Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to …6.1
- CVE-2026-81915Concrete CMS below 9.5.3 does not perform an object-level au…5.3
- CVE-2026-81916Concrete CMS before 9.5.3 evaluated the authorization check …4.3
- CVE-2026-81917Concrete CMS below 9.5.3 does not apply HTML output escaping…5.4
- CVE-2026-81918Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the…4.8
- CVE-2026-81919Concrete CMS below 9.5.3 did not validate an anti-CSRF token…4.3
- CVE-2026-8192A security flaw has been discovered in Wavlink NU516U1 M16U1…8.8
Are you affected by CVE-2026-81914?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
