Workload identity attestation generated before login host validation in Snowflake drivers
Summary
| CVE | CVE-2026-86600 |
|---|---|
| State | PUBLISHED |
| Assigner | SNOWFLAKE |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-08 16:18:29 UTC |
| Updated | 2026-09-10 16:18:03 UTC |
| Description | In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake for its remaining lifetime in accounts where that workload identity is already registered. On Azure, the token audience is also taken from connection configuration. Combined with an attacker-controlled host, the driver can request a Managed Identity access token scoped to a non-Snowflake Azure resource and deliver it to the attacker. That path is the only case in which impact extends beyond Snowflake; it is bounded by the token lifetime and the managed identity’s permissions. Successful exploitation requires WORKLOAD_IDENTITY authentication on a workload that already has an ambient cloud identity. Patched driver versions restrict this authenticator to recognized Snowflake hosts. Users must manually upgrade. |
Risk And Classification
Primary CVSS: v3.1 8.2 HIGH from 412d305a-227d-44f9-a262-a31ba44f2aea
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
EPSS: 0.003090000 probability, percentile 0.234440000 (date 2026-09-10)
Problem Types: CWE-441 | CWE-522 | CWE-522 Insufficiently Protected Credentials | CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 412d305a-227d-44f9-a262-a31ba44f2aea | Secondary | 8.2 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 8.2 | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Snowflake | Snowflake Connector For Python | affected 3.14.1 4.7.3 python | Not specified |
| CNA | Snowflake | Snowflake Go Driver | affected 1.15.0 1.19.1 semver | Not specified |
| CNA | Snowflake | Snowflake Go Driver | affected 2.0.0 2.2.0 semver | Not specified |
| CNA | Snowflake | Snowflake JDBC Driver | affected 3.24.0 4.3.4 maven | Not specified |
| CNA | Snowflake | Snowflake JDBC Driver FIPS | affected 3.24.0 4.3.4 maven | Not specified |
| CNA | Snowflake | Snowflake JDBC Driver Thin | affected 3.24.0 4.3.4 maven | Not specified |
| CNA | Snowflake | Snowflake Node.js Driver | affected 2.1.1 3.3.0 semver | Not specified |
| CNA | Snowflake | Snowflake Connector For .NET | affected 4.7.0 6.1.0 semver | Not specified |
| CNA | Snowflake | Snowflake ODBC Driver | affected 3.9.0 3.20.0 semver | Not specified |
| CNA | Snowflake | Snowflake PHP PDO Driver | affected 3.6.0 4.2.0 semver | Not specified |
| CNA | Snowflake | Snowflake Libsnowflakeclient | affected 2.2.0 2.10.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| docs.snowflake.com/en/release-notes/clients-drivers/golang-2026 | 412d305a-227d-44f9-a262-a31ba44f2aea | docs.snowflake.com | |
| docs.snowflake.com/en/release-notes/clients-drivers/jdbc-2026 | 412d305a-227d-44f9-a262-a31ba44f2aea | docs.snowflake.com | |
| docs.snowflake.com/en/release-notes/clients-drivers/php-pdo-2026 | 412d305a-227d-44f9-a262-a31ba44f2aea | docs.snowflake.com | |
| github.com/snowflakedb/libsnowflakeclient/releases/tag/v2.10.0 | 412d305a-227d-44f9-a262-a31ba44f2aea | github.com | |
| docs.snowflake.com/en/release-notes/clients-drivers/nodejs-2026 | 412d305a-227d-44f9-a262-a31ba44f2aea | docs.snowflake.com | |
| github.com/snowflakedb/snowflake-connector-python/releases/tag/v4.7.3 | 412d305a-227d-44f9-a262-a31ba44f2aea | github.com | |
| docs.snowflake.com/en/release-notes/clients-drivers/odbc-2026 | 412d305a-227d-44f9-a262-a31ba44f2aea | docs.snowflake.com | |
| docs.snowflake.com/en/release-notes/clients-drivers/dotnet-2026 | 412d305a-227d-44f9-a262-a31ba44f2aea | docs.snowflake.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.