Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85528— Snowflake JDBC Driver auto-configuration account validation permits credential redirection

Quick assessment

Affected
Snowflake Snowflake JDBC Driver
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Snowflake JDBC 驱动版本 4.2.0 至 4.3.3 对自动配置中的账户标识符缺乏适当的输入验证,导致携带凭证的登录请求可被重定向至攻击者选定的 HTTPS 端点。若攻击者能够控制 的值,则可使驱动将可复用的登录凭证发送至攻击者指定的主机,并凭此凭证重放请求以获取该凭证所授予的权限。成功利用此漏洞需要满足以下条件:应用程序使用 连接串,且其 配置中未显式指定 参数,同时存在一个较低信任级别的用户主体(principal)能够设置 值;普通的 JDBC URL 不受此漏洞影响。该漏洞的修复版本为 Sno

CVSS 5.3 · Medium EPSS 0.18% · P8

Affected Version Matrix 1

VendorProduct Version RangeStatus
Snowflake Snowflake JDBC Driver 4.2.0< 4.3.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85528

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Snowflake JDBC Driver auto-configuration account validation permits credential redirection
Source: CVE Program / CVE List V5
Vulnerability Description
Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint. An attacker able to control the account value could cause the driver to transmit a reusable login credential to a host of their choosing and replay it to obtain the privileges granted to that credential. Successful exploitation requires an application using jdbc:snowflake:auto with a connections.toml section that omits an explicit host and a lower-trust principal able to set the account value; ordinary JDBC URLs are unaffected. The fix is available in Snowflake JDBC Driver version 4.3.4. Users must manually upgrade.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Snowflake Snowflake JDBC Driver 4.2.0 ~ 4.3.4 -

II. Public POCs for CVE-2026-85528

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85528

登录查看更多情报信息。

Vendor Pages for CVE-2026-85528 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85528

No comments yet


Leave a comment