Sensitive information written to logs by Snowflake drivers
Summary
| CVE | CVE-2026-86597 |
|---|---|
| State | PUBLISHED |
| Assigner | SNOWFLAKE |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-08 09:18:21 UTC |
| Updated | 2026-09-08 19:12:59 UTC |
| Description | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did not cover all affected log paths and data types. An attacker with read access to the log destination, whether the local filesystem, a log aggregation service, or a CI/CD artifact store, could obtain credentials and decryption keys that, if still valid at the time of access, could be used to authenticate to the corresponding Snowflake account or cloud-storage object. Successful exploitation requires read access to the log destination, and impact is bounded by credential lifetime and object scope. The fix is available in the patched versions listed above. Users must manually upgrade and should securely delete previously generated diagnostic logs containing sensitive information where retention is not required. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from 412d305a-227d-44f9-a262-a31ba44f2aea
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
EPSS: 0.000870000 probability, percentile 0.003920000 (date 2026-09-08)
Problem Types: CWE-532 | CWE-532 Insertion of Sensitive Information into Log File
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 412d305a-227d-44f9-a262-a31ba44f2aea | Secondary | 6.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 6.5 | MEDIUM | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Snowflake | Snowflake Connector For Python | affected 4.7.3 python | Not specified |
| CNA | Snowflake | Snowflake Go Driver | affected 2.2.0 semver | Not specified |
| CNA | Snowflake | Snowflake JDBC Driver | affected 4.3.4 maven | Not specified |
| CNA | Snowflake | Snowflake Node.js Driver | affected 3.3.0 npm | Not specified |
| CNA | Snowflake | Snowflake PHP PDO Driver | affected 3.4.0 4.2.0 semver | Not specified |
| CNA | Snowflake | Snowflake ODBC Driver | affected 3.16.0 3.20.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| docs.snowflake.com/en/release-notes/clients-drivers/golang-2026 | 412d305a-227d-44f9-a262-a31ba44f2aea | docs.snowflake.com | |
| docs.snowflake.com/en/release-notes/clients-drivers/jdbc-2026 | 412d305a-227d-44f9-a262-a31ba44f2aea | docs.snowflake.com | |
| docs.snowflake.com/en/release-notes/clients-drivers/php-pdo-2026 | 412d305a-227d-44f9-a262-a31ba44f2aea | docs.snowflake.com | |
| docs.snowflake.com/en/release-notes/clients-drivers/nodejs-2026 | 412d305a-227d-44f9-a262-a31ba44f2aea | docs.snowflake.com | |
| github.com/snowflakedb/snowflake-connector-python/releases/tag/v4.7.3 | 412d305a-227d-44f9-a262-a31ba44f2aea | github.com | |
| docs.snowflake.com/en/release-notes/clients-drivers/odbc-2026 | 412d305a-227d-44f9-a262-a31ba44f2aea | docs.snowflake.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.