In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake for its remaining lifetime in accounts where that workload identity is already registered. On Azure, the token audience is also taken from connection configuration. Combined with an attacker-controlled host, the driver can request a Managed Identity access token scoped to a non-Snowflake Azure resource and deliver it to the attacker. That path is the only case in which impact extends beyond Snowflake; it is bounded by the token lifetime and the managed identity’s permissions. Successful exploitation requires WORKLOAD_IDENTITY authentication on a workload that already has an ambient cloud identity. Patched driver versions restrict this authenticator to recognized Snowflake hosts. Users must manually upgrade.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Snowflake
Subscribe
|
Libsnowflakeclient
Subscribe
Snowflake-connector-python
Subscribe
Snowflake Connector For .net
Subscribe
Snowflake Connector For Python
Subscribe
Snowflake Go Driver
Subscribe
Snowflake Jdbc Driver
Subscribe
Snowflake Node.js Driver
Subscribe
Snowflake Odbc Driver
Subscribe
Snowflake Php Pdo Driver
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Snowflake
Snowflake libsnowflakeclient Snowflake snowflake-connector-python Snowflake snowflake Connector For .net Snowflake snowflake Connector For Python Snowflake snowflake Go Driver Snowflake snowflake Jdbc Driver Snowflake snowflake Node.js Driver Snowflake snowflake Odbc Driver Snowflake snowflake Php Pdo Driver |
|
| Vendors & Products |
Snowflake
Snowflake libsnowflakeclient Snowflake snowflake-connector-python Snowflake snowflake Connector For .net Snowflake snowflake Connector For Python Snowflake snowflake Go Driver Snowflake snowflake Jdbc Driver Snowflake snowflake Node.js Driver Snowflake snowflake Odbc Driver Snowflake snowflake Php Pdo Driver |
Tue, 08 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake for its remaining lifetime in accounts where that workload identity is already registered. On Azure, the token audience is also taken from connection configuration. Combined with an attacker-controlled host, the driver can request a Managed Identity access token scoped to a non-Snowflake Azure resource and deliver it to the attacker. That path is the only case in which impact extends beyond Snowflake; it is bounded by the token lifetime and the managed identity’s permissions. Successful exploitation requires WORKLOAD_IDENTITY authentication on a workload that already has an ambient cloud identity. Patched driver versions restrict this authenticator to recognized Snowflake hosts. Users must manually upgrade. | |
| Title | Workload identity attestation generated before login host validation in Snowflake drivers | |
| Weaknesses | CWE-441 CWE-522 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: SNOWFLAKE
Published:
Updated: 2026-09-08T18:04:40.924Z
Reserved: 2026-09-08T08:32:19.278Z
Link: CVE-2026-86600
No data.
Status : Awaiting Analysis
Published: 2026-09-08T16:18:29.943
Modified: 2026-09-08T19:20:14.797
Link: CVE-2026-86600
No data.
OpenCVE Enrichment
Updated: 2026-09-08T20:34:44Z