CVE-2026-86600: Workload identity attestation generated before login host validation in Snowflake drivers

Published Sep 8, 2026
·
Updated

In affected Snowflake drivers, WORKLOADIDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake for its remaining lifetime in accounts where that workload identity is already registered. On Azure, the token audience is also taken from connection configuration. Combined with an attacker-controlled host, the driver can request a Managed Identity access token scoped to a non-Snowflake Azure resource and deliver it to the attacker. That path is the only case in which impact extends beyond Snowflake; it is bounded by the token lifetime and the managed identity’s permissions. Successful exploitation requires WORKLOADIDENTITY authentication on a workload that already has an ambient cloud identity. Patched driver versions restrict this authenticator to recognized Snowflake hosts. Users must manually upgrade.

Affected Software

1 affected component
Snowflake Snowflake drivers

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Snowflake drivers (WORKLOAD_IDENTITY authenticator) to a version that resolves this vulnerability.

    Fixed in Patched driver versions restrict this authenticator to recognized Snowflake hosts.
  2. Compensating control

    Ensure WORKLOAD_IDENTITY authentication is only allowed on workloads where the configured connection host is a recognized Snowflake endpoint (since impacted drivers minted/attached tokens without verifying the host).

  3. Operational

    If a token was potentially captured during exploitation, treat any WORKLOAD_IDENTITY managed-identity access tokens as compromised and revoke/let them expire; captured tokens can be replayed to Snowflake for their remaining lifetime.

Event History

Sep 8, 2026
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Exposure requires a Snowflake driver using WORKLOAD_IDENTITY authentication on a workload with an ambient cloud identity, where that workload identity is already registered with Snowflake. Deployments not using this authenticator do not meet the stated exploitation prerequisites.

2

What access does an attacker need to exploit it?

The attacker must be able to modify the connection configuration, including directing the driver to an attacker-controlled host. Exploitation does not require user interaction, but it depends on the driver minting a fresh workload-identity token from the affected workload.

3

What is the impact of a captured token?

A captured workload-identity attestation can be replayed to Snowflake for the remainder of its lifetime where the identity is registered. On Azure, attacker-controlled host and audience configuration can cause a Managed Identity token for a non-Snowflake Azure resource to be sent to the attacker; the impact is limited by the token lifetime and that identity's permissions.

4

What should teams do if they cannot upgrade immediately?

Prevent untrusted parties from modifying Snowflake connection configuration, especially the configured host and, on Azure, the token audience. The stated fix is to manually upgrade to patched driver versions, which restrict WORKLOAD_IDENTITY authentication to recognized Snowflake hosts.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203