Improper Input Validation in Snowflake CLI Affects SQL Execution
CVE-2026-92903
8.2HIGH
What is CVE-2026-92903?
The Snowflake CLI prior to version 3.27.0 is susceptible to improper input validation, allowing attackers to execute arbitrary SQL commands within the victim's Snowflake context. By injecting unsanitized user inputs into SQL strings, an attacker can manipulate execution paths, thus performing unauthorized actions. Security measures should involve restricting write or pull-request access to project repositories that utilize Snowflake CLI and ensuring users upgrade to version 3.27.0 for enhanced security protections.
Affected Version(s)
Snowflake CLI 0 < 3.27.0
Snowflake CLI 0 < 3.27.0
