๐Ÿ” CVE Alert

CVE-2026-85528

MEDIUM 5.3

Snowflake JDBC Driver auto-configuration account validation permits credential redirection

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint. An attacker able to control the account value could cause the driver to transmit a reusable login credential to a host of their choosing and replay it to obtain the privileges granted to that credential. Successful exploitation requires an application using jdbc:snowflake:auto with a connections.toml section that omits an explicit host and a lower-trust principal able to set the account value; ordinary JDBC URLs are unaffected. The fix is available in Snowflake JDBC Driver version 4.3.4. Users must manually upgrade.

CWE CWE-20 CWE-918
Vendor snowflake
Product snowflake jdbc driver
Published Sep 4, 2026
Last Updated Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for snowflake snowflake jdbc driver

Be the first to know when new medium vulnerabilities affecting snowflake snowflake jdbc driver are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Snowflake / Snowflake JDBC Driver
4.2.0 < 4.3.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
docs.snowflake.com: https://docs.snowflake.com/en/release-notes/clients-drivers/jdbc-2026#version-434-sep-03-2026