https://seclists.org/oss-sec/2026/q3/797: CVE-2026-86792: Apache Airflow Apache Kafka provider: Connection-editor mote code execution on the Scheduler via Kafka connection callback configuration

Published Sep 15, 2026
·
Updated

Affected Software

1 affected component
apache-airflow-providers-apache-kafka<2.0.0

Frequently Asked Questions

1

Which deployments are exposed to scheduler-side code execution?

Deployments using plain Kafka brokers or Amazon MSK are exposed when the Kafka event producer is enabled through either dag_run_events_enabled or task_instance_events_enabled. Both settings are disabled by default, so deployments that have not enabled either event type do not build the affected client in the scheduler process.

2

What access does an attacker need to exploit this issue?

An attacker needs permission to edit Airflow connections and must be able to place a dotted Python path in the Kafka connection extra configuration. The vulnerable provider resolves that path and supplies the resulting callable to the Kafka client.

3

Are Google Managed Kafka deployments affected?

No. The Google Managed Kafka code path replaces any user-supplied oauth_cb value, preventing the affected callback configuration from being used.

4

What is the recommended remediation?

Upgrade apache-airflow-providers-apache-kafka to version 2.0.0 or later. This release adds an allowlist configuration option for connection-string callbacks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203