PT-2026-102497 · Apache Airflow · Apache Airflow Teradata Provider

·

CVE-2026-81862

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions apache-airflow-providers-teradata versions prior to 3.7.0
Description The Teradata provider in Apache Airflow embeds cloud storage credentials directly into SQL statements as plain string literals within the CREATE MULTISET TABLE ... LOCATION statement. This occurs when using S3ToTeradataOperator or AzureBlobStorageToTeradataOperator with a private bucket and no teradata authorization name configured. Consequently, credentials are exposed in two locations: the Airflow task logs and Teradata's DBQL query logs and live monitoring views. Specifically, S3ToTeradataOperator may expose runtime AWS credentials and STS session tokens in Airflow logs, while AzureBlobStorageToTeradataOperator exposes storage account keys within Teradata's internal logs.
Recommendations Upgrade to apache-airflow-providers-teradata version 3.7.0 or later. Configure teradata authorization name with a Teradata AUTHORIZATION object to prevent credentials from being inlined. Rotate any credentials previously used through the inline path.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81862

Affected Products

Apache Airflow Teradata Provider