Authentication Vulnerability in Snowflake Drivers Affects Various Platforms
CVE-2026-86600

8.2HIGH

What is CVE-2026-86600?

In specific versions of Snowflake drivers, a vulnerability exists that allows the WORKLOAD_IDENTITY authentication to improperly handle requests for a cloud workload-identity token. This flaw permits an attacker to modify the connection configuration, leading to potential exploitation where a crafted connection could direct tokens to a malicious entity. The attacker could then utilize these tokens to gain access to Snowflake accounts. Specifically, if the attacker's host is configured as a valid endpoint, they can intercept a new attestation and misuse it during its lifetime. The impact is critical for accounts with an existing workload identity in systems like Azure, where tokens could also be obtained for non-Snowflake resources. The patched versions of these drivers limit WORKLOAD_IDENTITY authentication requests strictly to recognized Snowflake hosts, prompting users to upgrade manually to mitigate risks.

Affected Version(s)

Snowflake Connector for .NET 4.7.0 < 6.1.0

Snowflake Connector for Python 3.14.1 < 4.7.3

Snowflake Go Driver 1.15.0 < 2.2.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.