PT-2026-94226 · Snowflake · Snowflake Cli
CVE-2026-92903
·
Published
2026-09-17
·
Updated
2026-09-17
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Snowflake CLI versions prior to 3.27.0
Description
Improper input validation allows unsanitized user-controlled values to be interpolated into SQL strings executed as multi-statement queries. An attacker can execute arbitrary SQL statements within the victim's Snowflake session and active role by providing a malicious project configuration file or crafted command-line input. Exploitation requires write or pull-request access to a project repository where the CI/CD pipeline runs the CLI under an elevated service account role, or the ability to provide untrusted input to automation wrapping the CLI. The impact is restricted by the privileges of the configured Snowflake role during execution.
Recommendations
Update to version 3.27.0.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snowflake Cli