← Back to search

CVE-2026-86792

8.8 HIGHpublic exploit available

Published 2026-09-16 · Updated 2026-09-18

AI risk analysis

Summary
The flaw allows a user with permission to edit Airflow connections to execute arbitrary code in the scheduler process, which is outside the typical scope of their privileges.
Exploitability
Exploitation requires access to edit Airflow connections and has a moderate level of difficulty due to the need to craft a specific `extra` field payload.
Blast radius
If exploited, the impact is high, as it could lead to full control of the Airflow scheduler process, potentially affecting the entire system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to apache-airflow-providers-apache-kafka 2.0.0 or later, which introduces an allowlist configuration option for connection-string callbacks.
rceairflowkafkapythoncode-execution

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka client which invokes them. Deployments that have enabled the Kafka event producer — `dag_run_events_enabled` or `task_instance_events_enabled`, both disabled by default — build that client inside the scheduler process, so a user whose only privilege is editing Airflow connections gains arbitrary code execution in the control plane; the Airflow security model limits connection-configuration users to code execution on workers, not the scheduler. Deployments using Google Managed Kafka are not affected, because that code path overwrites any user-supplied `oauth_cb`; plain brokers and Amazon MSK are exposed. Users are recommended to upgrade to apache-airflow-providers-apache-kafka 2.0.0 or later, which adds an allowlist configuration option for connection-string callbacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-470

Vendors

apache

Products

apache-airflow-providers-apache-kafka

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.