PT-2026-85440 · Snowflake · Snowflake Jdbc Driver
CVE-2026-85528
·
Published
2026-09-04
·
Updated
2026-09-04
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Snowflake JDBC Driver versions 4.2.0 through 4.3.3
Description
Improper input validation of the auto-configuration account identifier allows a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint. An attacker who can control the account value can cause the driver to transmit a reusable login credential to a host of their choosing and replay it to obtain the privileges granted to that credential. This issue affects applications using
jdbc:snowflake:auto with a connections.toml section that omits an explicit host and a lower-trust principal capable of setting the account value. Ordinary JDBC URLs are not affected.Recommendations
Upgrade Snowflake JDBC Driver to version 4.3.4.
Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snowflake Jdbc Driver