CVE-2026-81862: Apache Airflow Teradata provider: Teradata transfer operators embed cloud storage credentials in SQL text, task logs and Teradata query logs
Apache Airflow Teradata provider before 3.7.0 embeds cloud storage credentials in SQL and logs (CVE-2026-81862).
CVE-2026-81862, rated moderate, affects the Apache Airflow Teradata provider before version 3.7.0. S3ToTeradataOperator and AzureBlobStorageToTeradataOperator interpolate private source-bucket credentials as plain string literals into the CREATE MULTISET TABLE ... LOCATION statement. Those secrets can appear in the SQL text, Airflow task logs, and Teradata query logs. The disclosure does not report active exploitation.
- CVE-2026-81862 is rated moderate and fixed in Teradata provider 3.7.0.
- S3ToTeradataOperator and AzureBlobStorageToTeradataOperator embed bucket credentials in SQL.
- Secrets can land in SQL text, Airflow task logs, and Teradata query logs.
- The issue applies when the source bucket is private.
- No active exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-818626.5—Cloud credential leak in Apache Airflow Teradata providerpublished · Apache Software Foundation apache-airflow-providers-teradata
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-81862 | Cloud credential leak in Apache Airflow Teradata provider Apache Airflow's Teradata provider embeds cloud storage credentials as plain string literals in the CREATE MULTISET TABLE ... LOCATION statement issued by S3ToTeradataOperator and AzureBlobStorageToTeradataOperator whenever the source is private and teradata_authorization_name is unset, which is the default. The statement is both executed and logged: S3 credentials from s3_hook.get_credentials(), including unmasked runtime instance-profile or IRSA session tokens, appear in the Airflow task log readable by any user with Dag log-view permission, while both operators write AWS or Azure credentials into Teradata DBQL query logs and live monitoring views that Airflow cannot mask and that persist for Teradata's log retention. Anyone who can read those logs can recover reusable cloud storage credentials. Only deployments that use either operator against a private bucket or container without a Teradata AUTHORIZATION object are affected. No public proof-of-concept is known, and the issue is not listed in CISA KEV. |
Posted by Shahar Epstein on Sep 29 Severity: moderate Affected versions: - Apache Airflow Teradata provider before 3.7.0 Description: Apache Airflow's Teradata provider embedded cloud storage credentials directly into SQL statements. `S3ToTeradataOperator` and `AzureBlobStorageToTeradataOperator` interpolate the source bucket's credentials as plain string literals into the `CREATE MULTISET TABLE ... LOCATION` statement whenever the bucket is private and no...
This source does not provide full text. Read it at seclists.org.