๐Ÿ” CVE Alert

CVE-2026-16870

HIGH 8.8

Multiple Security Vulnerabilities in Snowflake libsnowflakeclient

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim process later downloads, and impact would be limited to deployments where principals with different privilege levels share the same internal stage. A related out-of-bounds write in the same download path could allow memory corruption with attacker-controlled write primitives. An attacker may exploit this through a crafted initialization vector metadata field on a shared stage, and impact would be limited by the same stage-write precondition. Improper validation of connection parameters could allow an attacker-controlled input to redirect outbound authentication requests โ€” including credentials and tokens โ€” to an attacker-controlled endpoint. Impact is limited to embedding deployments where a lower-privileged principal can influence connection configuration while higher-privileged service credentials are in use. The fix is available in Snowflake libsnowflakeclient version 2.9.2. Users must manually upgrade.

CWE CWE-121 CWE-787 CWE-918
Vendor snowflake
Product snowflake libsnowflakeclient
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for snowflake snowflake libsnowflakeclient

Be the first to know when new high vulnerabilities affecting snowflake snowflake libsnowflakeclient are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Snowflake / Snowflake libsnowflakeclient
0.1.1 < 2.9.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/snowflakedb/libsnowflakeclient/releases/tag/v2.9.2