CVE-2026-85528: Snowflake JDBC Driver auto-configuration account validation permits credential redirection

Published Sep 4, 2026
·
Updated

Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint. An attacker able to control the account value could cause the driver to transmit a reusable login credential to a host of their choosing and replay it to obtain the privileges granted to that credential. Successful exploitation requires an application using jdbc:snowflake:auto with a connections.toml section that omits an explicit host and a lower-trust principal able to set the account value; ordinary JDBC URLs are unaffected. The fix is available in Snowflake JDBC Driver version 4.3.4. Users must manually upgrade.

Affected Software

2 affected components
Snowflake Snowflake JDBC driver>=4.2.0<=4.3.3
Snowflake Snowflake JDBC driver<4.3.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Snowflake JDBC Driver to a version that resolves this vulnerability.

    Fixed in 4.3.4
  2. Operational

    Manually upgrade Snowflake JDBC Driver from versions 4.2.0 through 4.3.3 to version 4.3.4.

Event History

Sep 4, 2026
CVE Published
via MITRE·08:36 AM
Data Sourced
via MITRE·08:36 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Only applications using jdbc:snowflake:auto with a connections.toml section that does not specify an explicit host are affected. Ordinary JDBC URLs are unaffected.

2

What access does an attacker need to exploit this?

The attacker must be a lower-trust principal who can set the auto-configuration account value. They can use that control to redirect a credential-bearing login request to an HTTPS endpoint they select.

3

What is the impact if exploitation succeeds?

The redirected request can disclose a reusable login credential to the attacker. The attacker can replay that credential with the privileges granted to it.

4

How can the issue be remediated or mitigated?

Manually upgrade the Snowflake JDBC Driver to version 4.3.4. Until upgraded, avoid the affected auto-configuration condition by using an explicit host in the relevant connections.toml section and prevent lower-trust principals from setting the account value.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203