5.3
CVE-2026-85528
- EPSS 0.18%
- Veröffentlicht 04.09.2026 08:36:28
- Zuletzt bearbeitet 10.09.2026 16:17:58
- Erkennungen
Snowflake JDBC Driver auto-configuration account validation permits credential redirection
Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint. An attacker able to control the account value could cause the driver to transmit a reusable login credential to a host of their choosing and replay it to obtain the privileges granted to that credential. Successful exploitation requires an application using jdbc:snowflake:auto with a connections.toml section that omits an explicit host and a lower-trust principal able to set the account value; ordinary JDBC URLs are unaffected. The fix is available in Snowflake JDBC Driver version 4.3.4, including the snowflake-jdbc-fips and snowflake-jdbc-thin. Users must manually upgrade.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSnowflake
≫
Produkt
Snowflake JDBC Driver
Default Statusunaffected
Version
4.2.0
Version <
4.3.4
Status
affected
HerstellerSnowflake
≫
Produkt
Snowflake JDBC Driver (FIPS)
Default Statusunaffected
Version
4.2.0
Version <
4.3.4
Status
affected
HerstellerSnowflake
≫
Produkt
Snowflake JDBC Driver (Thin)
Default Statusunaffected
Version
4.2.0
Version <
4.3.4
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.078 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 412d305a-227d-44f9-a262-a31ba44f2aea | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://docs.snowflake.com/en/release-notes/clients-drivers/jdbc-2026#version-434-sep-03-2026