PT-2026-94226 · Snowflake · Snowflake Cli

CVE-2026-92903

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Snowflake CLI versions prior to 3.27.0
Description Improper input validation allows unsanitized user-controlled values to be interpolated into SQL strings executed as multi-statement queries. An attacker can execute arbitrary SQL statements within the victim's Snowflake session and active role by providing a malicious project configuration file or crafted command-line input. Exploitation requires write or pull-request access to a project repository where the CI/CD pipeline runs the CLI under an elevated service account role, or the ability to provide untrusted input to automation wrapping the CLI. The impact is restricted by the privileges of the configured Snowflake role during execution.
Recommendations Update to version 3.27.0.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92903

Affected Products

Snowflake Cli