CVE-2026-86600

Source
https://cve.org/CVERecord?id=CVE-2026-86600
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86600.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86600
Published
2026-09-08T15:48:45Z
Modified
2026-09-12T08:07:30Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Workload identity attestation generated before login host validation in Snowflake drivers
Details

In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake for its remaining lifetime in accounts where that workload identity is already registered. On Azure, the token audience is also taken from connection configuration. Combined with an attacker-controlled host, the driver can request a Managed Identity access token scoped to a non-Snowflake Azure resource and deliver it to the attacker. That path is the only case in which impact extends beyond Snowflake; it is bounded by the token lifetime and the managed identity’s permissions. Successful exploitation requires WORKLOAD_IDENTITY authentication on a workload that already has an ambient cloud identity. Patched driver versions restrict this authenticator to recognized Snowflake hosts. Users must manually upgrade.

Database specific
{
    "cna_assigner": "SNOWFLAKE",
    "cwe_ids": [
        "CWE-441",
        "CWE-522"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86600.json"
}
References

Affected packages

Git / github.com/snowflakedb/gosnowflake

Affected ranges

Type
GIT
Repo
https://github.com/snowflakedb/gosnowflake
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.15.0"
        },
        {
            "last_affected": "1.19.1"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.2.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}
Type
GIT
Repo
https://github.com/snowflakedb/libsnowflakeclient
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.2.0"
        },
        {
            "fixed": "2.10.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/snowflakedb/pdo_snowflake
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Introduced
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.1.1"
        },
        {
            "fixed": "3.3.0"
        },
        {
            "introduced": "3.6.0"
        },
        {
            "fixed": "4.2.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}
Type
GIT
Repo
https://github.com/snowflakedb/snowflake-connector-net
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "4.7.0"
        },
        {
            "fixed": "6.1.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}
Type
GIT
Repo
https://github.com/snowflakedb/snowflake-connector-python
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.14.1"
        },
        {
            "fixed": "4.7.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}
Type
GIT
Repo
https://github.com/snowflakedb/snowflake-jdbc
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.24.0"
        },
        {
            "fixed": "4.3.4"
        },
        {
            "introduced": "3.9.0"
        },
        {
            "fixed": "3.20.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

3.*
3.13.21
3.13.22
v0.*
v0.1.3
v0.1.4
v0.2.0
v0.2.1
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v1.*
v1.0.0
v1.0.1
v1.0.2
v1.1.0
v1.1.1
v1.15.0
v1.16.0
v1.17.0
v1.17.1
v1.18.0
v1.18.1
v1.19.0
v1.19.1
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.2.5
v1.2.6
v1.2.7
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.0
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v2.6.0
v2.7.0
v2.7.1
v2.8.0
v2.9.0
v2.9.1
v2.9.2
v3.*
v3.0.0
v3.0.1
v3.0.2
v3.0.3
v3.1.0
v3.10.0
v3.10.1
v3.10.2
v3.10.3
v3.11.0
v3.11.1
v3.12.0
v3.12.1
v3.12.11
v3.12.12
v3.12.14
v3.12.16
v3.12.2
v3.12.3
v3.12.4
v3.12.5
v3.12.6
v3.12.7
v3.12.9
v3.13.0
v3.13.1
v3.13.10
v3.13.12
v3.13.13
v3.13.14
v3.13.15
v3.13.16
v3.13.17
v3.13.18
v3.13.19
v3.13.2
v3.13.20
v3.13.21
v3.13.22
v3.13.23
v3.13.24
v3.13.25
v3.13.26
v3.13.27
v3.13.28
v3.13.29
v3.13.3
v3.13.30
v3.13.31
v3.13.32
v3.13.33
v3.13.4
v3.13.5
v3.13.6
v3.13.7
v3.13.8
v3.13.9
v3.14.0
v3.14.1
v3.14.2
v3.14.3
v3.14.4
v3.14.5
v3.15.0
v3.15.1
v3.16.0
v3.16.1
v3.17.0
v3.17.1
v3.17.2
v3.17.3
v3.18.0
v3.19.0
v3.19.1
v3.2.0
v3.24.0
v3.24.1
v3.24.2
v3.25.0
v3.25.1
v3.26.0
v3.26.1
v3.27.0
v3.27.1
v3.28.0
v3.6.0
v3.7.0
v3.9.0
v3.9.1
v3.9.2
v4.*
v4.0.0
v4.0.1
v4.0.2
v4.1.0
v4.1.1
v4.2.0
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.4.0
v4.5.0
v4.6.0
v4.7.0
v4.7.1
v4.8.0
v5.*
v5.0.0
v5.1.0
v5.2.0
v5.2.1
v5.3.0
v5.4.0
v5.4.1
v5.5.0
v5.6.0
v5.7.0
v6.*
v6.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86600.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "87674454368960583278253932243093302631",
                "252526441228695263399039897143504444639",
                "124550780036735250839349245119655025324",
                "168648994019949861507178290233732502679"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-86600-e7934dd2",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/snowflakedb/snowflake-jdbc/commit/21e98c74145461212ff3a47f3540bc1fd3026a5e",
        "target": {
            "file": "src/main/java/net/snowflake/client/jdbc/SnowflakeDriver.java"
        }
    }
]
vanir_signatures_modified
"2026-09-12T08:07:30Z"