PT-2026-58028 · Snowflake · Snowflake Sqlalchemy

CVE-2026-15736

·

Published

2026-07-14

·

Updated

2026-09-10

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Snowflake SQLAlchemy versions prior to 1.11.0
Description Multiple security issues exist in the library. Improper handling of user-supplied column identifiers during merge operations allows SQL injection via attacker-controlled input keys, which can be exploited through request field names in a dynamic upsert endpoint to read data or modify values within a MERGE statement. Additionally, improper literal rendering of bound parameters in specific Snowflake table creation queries enables SQL injection, potentially leading to arbitrary data exfiltration when user-controlled data is passed through the query-building API. Furthermore, improper forwarding of connection configuration parameters may allow an attacker to force the library to read arbitrary local files and transmit the contents to an external endpoint in environments that accept user-controlled connection parameters.
Recommendations Update to version 1.11.0.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15736
GHSA-8G6F-QW9X-4Q6Q
PYSEC-2026-3921

Affected Products

Snowflake Sqlalchemy