CVE-2026-92903

Source
https://cve.org/CVERecord?id=CVE-2026-92903
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92903.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92903
Published
2026-09-17T10:49:59Z
Modified
2026-09-19T03:47:31Z
Severity
  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Improper Input Validation in Snowflake CLI Versions Allow Unsanitized User-Controlled Values to be Interpolated into SQL Strings
Details

Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries. An attacker who is able to supply a malicious project configuration file or craft command-line input can cause Snowflake CLI to execute attacker-controlled SQL statements in the context of the victim's Snowflake session and active role. Successful exploitation requires either write or pull-request access to a project repository whose CI/CD pipeline runs Snowflake CLI under an elevated service account role, or the ability to supply untrusted input to CLI-wrapping automation. Impact is limited by the privileges held by the configured Snowflake role at execution time. The fix is available in Snowflake CLI version 3.27.0, which also addresses several additional security findings. Users must manually upgrade.

Database specific
{
    "cna_assigner": "SNOWFLAKE",
    "cwe_ids": [
        "CWE-89"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92903.json"
}
References

Affected packages

Git / github.com/snowflakedb/snowflake-cli

Affected ranges

Type
GIT
Repo
https://github.com/snowflakedb/snowflake-cli
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.27.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.0.1-a
Other
dcm-prpr-20250804
na-preview
v0.*
v0.1.0
v0.1.1
v0.1.10
v0.1.11
v0.1.12
v0.1.13
v0.1.14
v0.1.15
v0.1.16
v0.1.17
v0.1.18
v0.1.19
v0.1.2
v0.1.2-a
v0.1.20
v0.1.21
v0.1.22
v0.1.23
v0.1.24
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.1.9
v0.2.0
v0.2.1
v0.2.2
v0.2.3
v0.2.4
v0.2.5
v0.2.7
v0.2.8
v0.2.9
v1.*
v1.0.0
v1.0.1
v1.0.1-rc1
v1.0.1-rc2
v1.1.0
v1.1.0-rc1
v2.*
v2.0.0
v2.0.0-alpha.1
v2.0.0-alpha.2
v2.0.0-alpha.3
v2.0.0rc0
v2.0.0rc1
v2.0.0rc2
v2.0.0rc3
v2.1.0-rc0
v2.2.0-rc0
v2.3.0-rc0
v2.7.0-rc0
v3.*
v3.0.0-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92903.json"