PT-2026-58028 · Snowflake · Snowflake Sqlalchemy
CVE-2026-15736
·
Published
2026-07-14
·
Updated
2026-09-10
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Snowflake SQLAlchemy versions prior to 1.11.0
Description
Multiple security issues exist in the library. Improper handling of user-supplied column identifiers during merge operations allows SQL injection via attacker-controlled input keys, which can be exploited through request field names in a dynamic upsert endpoint to read data or modify values within a MERGE statement. Additionally, improper literal rendering of bound parameters in specific Snowflake table creation queries enables SQL injection, potentially leading to arbitrary data exfiltration when user-controlled data is passed through the query-building API. Furthermore, improper forwarding of connection configuration parameters may allow an attacker to force the library to read arbitrary local files and transmit the contents to an external endpoint in environments that accept user-controlled connection parameters.
Recommendations
Update to version 1.11.0.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snowflake Sqlalchemy