Sensitive Information Exposure in Snowflake Drivers
CVE-2026-86597
6.5MEDIUM
What is CVE-2026-86597?
A significant security issue within Snowflake drivers allows sensitive information, including authentication tokens and encryption keys, to be logged unintentionally. This occurs when log redaction fails to cover all relevant paths and data types. Attackers with access to these logs, whether from local file systems or log aggregation services, can exploit this to obtain valid credentials and gain unauthorized access to Snowflake accounts or cloud-storage objects. It is crucial for users to upgrade to the latest patched versions and securely delete any sensitive logs that are no longer required for retention.
Affected Version(s)
Snowflake Connector for Python 0 < 4.7.3
Snowflake Go Driver 0 < 2.2.0
Snowflake JDBC Driver 0 < 4.3.4
