Description
The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the Dag author, and one that needs no Teradata credentials of its own - could therefore supply SQL fragments that execute under the connection the task runs as, and could additionally redirect the task at any other connection defined in the deployment, because the connection id was itself a free-text Param. Only deployments that run this example Dag, or a Dag copied from it, are affected; the provider's operator code is unchanged. Users of apache-airflow-providers-teradata are recommended to upgrade to version 3.7.0 or later, whose example constrains the Params to validated identifiers and a closed value set and removes connection selection and free-form option strings from trigger-time input. Upgrading does not change a Dag already copied from the example; users who copied it should apply the same constraints to their copy.
Published: 2026-09-29
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Patch Immediately
AI Analysis

Impact

An attacker can inject arbitrary Teradata SQL through unvalidated Dag Params in the compute-cluster example DAG. This allows execution of dangerous data definition and manipulation statements under the connection associated with the task. The vulnerability arises from the provider's operators directly templating free-text Dag Params into DDL, enabling code execution without requiring Teradata credentials from the attacker.

Affected Systems

Apache Airflow Teradata provider users who deploy the compute-cluster example DAG, or variants copied from it, with any version of the provider before 3.7.0. The effect is specific to deployments that expose the example DAG; the provider's core operator code remains unchanged.

Risk and Exploitability

The CVSS score is 6.3, indicating a moderate severity. Because the description indicates the flaw requires a user with permission to trigger the DAG—not necessarily a database admin—the risk is high for organizations that enable low-trust execution roles. The exact EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the lack of input validation combined with the potential to run arbitrary SQL indicates a severe threat. Attackers can manipulate the Dag Params to inject DDL and select arbitrary connections from the data source, enabling data exfiltration or structural changes in the Teradata environment.

Generated by OpenCVE AI on September 30, 2026 at 03:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade apache-airflow-providers-teradata to version 3.7.0 or later.
  • If the example DAG was copied, reapply the provider’s validation restrictions to any Dag Params and remove the free-text connection selector.
  • Disable or remove the compute-cluster example DAG from production environments that do not require it.
  • Enforce role-based access controls so that only authorized users can trigger the DAG and bind execution to a fixed, trusted connection.

Generated by OpenCVE AI on September 30, 2026 at 03:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description The Apache Airflow Teradata provider's compute-cluster example Dag declared every one of its Dag Params as unconstrained free text and templated them straight into the compute-cluster operators, which interpolate those values into Teradata DDL. A user who is permitted to trigger that Dag - a lower-trust role than the Dag author, and one that needs no Teradata credentials of its own - could therefore supply SQL fragments that execute under the connection the task runs as, and could additionally redirect the task at any other connection defined in the deployment, because the connection id was itself a free-text Param. Only deployments that run this example Dag, or a Dag copied from it, are affected; the provider's operator code is unchanged. Users of apache-airflow-providers-teradata are recommended to upgrade to version 3.7.0 or later, whose example constrains the Params to validated identifiers and a closed value set and removes connection selection and free-form option strings from trigger-time input. Upgrading does not change a Dag already copied from the example; users who copied it should apply the same constraints to their copy.
Title Apache Airflow Teradata provider: SQL injection via unvalidated Dag Params in the compute-cluster example Dag
Weaknesses CWE-89
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-29T18:28:37.380Z

Reserved: 2026-09-08T14:46:36.995Z

Link: CVE-2026-86843

cve-icon Vulnrichment

Updated: 2026-09-29T11:08:17.272Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T10:17:12.963

Modified: 2026-09-29T19:17:27.313

Link: CVE-2026-86843

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T04:00:15Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')