Input Validation Flaw in Snowflake JDBC Driver by Snowflake
CVE-2026-85528
5.3MEDIUM
What is CVE-2026-85528?
The Snowflake JDBC Driver versions 4.2.0 through 4.3.3 contains an improper input validation vulnerability concerning the auto-configuration account identifier. This flaw allows an attacker to manipulate the account value, potentially redirecting credential-bearing login requests to a malicious HTTPS endpoint. If successfully exploited, this vulnerability could enable an attacker to capture and replay login credentials, providing unauthorized access to privileges associated with those credentials. Affected users are advised to upgrade to version 4.3.4 to remediate this issue.
Affected Version(s)
Snowflake JDBC Driver 4.2.0 < 4.3.4
