Input Validation Flaw in Snowflake JDBC Driver by Snowflake
CVE-2026-85528

5.3MEDIUM

Key Information:

Vendor

Snowflake

Vendor
CVE Published:
4 September 2026

What is CVE-2026-85528?

The Snowflake JDBC Driver versions 4.2.0 through 4.3.3 contains an improper input validation vulnerability concerning the auto-configuration account identifier. This flaw allows an attacker to manipulate the account value, potentially redirecting credential-bearing login requests to a malicious HTTPS endpoint. If successfully exploited, this vulnerability could enable an attacker to capture and replay login credentials, providing unauthorized access to privileges associated with those credentials. Affected users are advised to upgrade to version 4.3.4 to remediate this issue.

Affected Version(s)

Snowflake JDBC Driver 4.2.0 < 4.3.4

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.