Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Christos Bisias

#32105of 57,593
8.8Total CVSS
Vulnerabilities · 1
PT-2026-93422
8.8
2026-09-16
Apache · Apache Airflow Apache Kafka Provider · CVE-2026-86792
**Name of the Vulnerable Software and Affected Versions** Apache Airflow Apache Kafka provider versions 1.15.0 through 1.9.9 **Description** The software resolves dotted-path strings found in a Kafka connection's `extra` field into Python callables using the `import string` function without an allowlist. These callables are then passed to the confluent-kafka client for invocation. In deployments where the Kafka event producer is enabled via `dag run events enabled` or `task instance events enabled`, the client is built within the scheduler process. This allows a user with permissions to edit Airflow connections to achieve arbitrary code execution in the control plane, bypassing the security model that typically limits such users to code execution on workers. This issue affects plain brokers and Amazon MSK, while Google Managed Kafka is not affected as it overwrites the `oauth cb` variable. **Recommendations** Upgrade to apache-airflow-providers-apache-kafka version 2.0.0 or later.