Improper Input Validation in Snowflake CLI Affects SQL Execution
CVE-2026-92903

8.2HIGH

Key Information:

Vendor

Snowflake

Vendor
CVE Published:
17 September 2026

What is CVE-2026-92903?

The Snowflake CLI prior to version 3.27.0 is susceptible to improper input validation, allowing attackers to execute arbitrary SQL commands within the victim's Snowflake context. By injecting unsanitized user inputs into SQL strings, an attacker can manipulate execution paths, thus performing unauthorized actions. Security measures should involve restricting write or pull-request access to project repositories that utilize Snowflake CLI and ensuring users upgrade to version 3.27.0 for enhanced security protections.

Affected Version(s)

Snowflake CLI 0 < 3.27.0

Snowflake CLI 0 < 3.27.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.