Authentication Vulnerability in Snowflake Drivers Affects Various Platforms
CVE-2026-86600
What is CVE-2026-86600?
In specific versions of Snowflake drivers, a vulnerability exists that allows the WORKLOAD_IDENTITY authentication to improperly handle requests for a cloud workload-identity token. This flaw permits an attacker to modify the connection configuration, leading to potential exploitation where a crafted connection could direct tokens to a malicious entity. The attacker could then utilize these tokens to gain access to Snowflake accounts. Specifically, if the attacker's host is configured as a valid endpoint, they can intercept a new attestation and misuse it during its lifetime. The impact is critical for accounts with an existing workload identity in systems like Azure, where tokens could also be obtained for non-Snowflake resources. The patched versions of these drivers limit WORKLOAD_IDENTITY authentication requests strictly to recognized Snowflake hosts, prompting users to upgrade manually to mitigate risks.
Affected Version(s)
Snowflake Connector for .NET 4.7.0 < 6.1.0
Snowflake Connector for Python 3.14.1 < 4.7.3
Snowflake Go Driver 1.15.0 < 2.2.0
