PT-2026-53310 · Snowflake · Snowflake Cli

CVE-2026-13746

·

Published

2026-06-29

·

Updated

2026-06-30

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Snowflake CLI versions prior to 3.19
Description Improper neutralization of local CLI parameters allows unintended SQL execution. A user can trigger this issue by providing crafted values to the Cortex SQL or object listing command paths, leading the Snowflake CLI to execute unauthorized SQL within the context of the user's session. Exploitation is limited to self-injection since parameters are supplied via local CLI arguments, and the impact is restricted to the privileges of the current session.
Recommendations Update Snowflake CLI to version 3.19.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13746

Affected Products

Snowflake Cli