Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-92903— Improper Input Validation in Snowflake CLI Versions Allow Unsanitized User-Controlled Values to be Interpolated into SQL Strings

Quick assessment

Affected
Snowflake Snowflake CLI
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Snowflake CLI 在 3.27.0 之前的版本存在输入验证不当的漏洞,导致未经净化的、由用户控制的值被直接插入到以多语句查询形式执行的 SQL 字符串中。攻击者若能提供恶意的项目配置文件或构造特定的命令行输入,可诱使 Snowflake CLI 在受害者的 Snowflake 会话及其当前激活角色上下文中执行由攻击者控制的 SQL 语句。 成功利用该漏洞需满足以下任一条件: 对某个项目的仓库具有写入权限或 Pull Request 提交权限,且该仓库的 CI/CD 管道以具备较高权限的服务账户角色运行 S

CVSS 8.2 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-92903

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Improper Input Validation in Snowflake CLI Versions Allow Unsanitized User-Controlled Values to be Interpolated into SQL Strings
Source: CVE Program / CVE List V5
Vulnerability Description
Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries. An attacker who is able to supply a malicious project configuration file or craft command-line input can cause Snowflake CLI to execute attacker-controlled SQL statements in the context of the victim's Snowflake session and active role. Successful exploitation requires either write or pull-request access to a project repository whose CI/CD pipeline runs Snowflake CLI under an elevated service account role, or the ability to supply untrusted input to CLI-wrapping automation. Impact is limited by the privileges held by the configured Snowflake role at execution time. The fix is available in Snowflake CLI version 3.27.0, which also addresses several additional security findings. Users must manually upgrade.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Snowflake Snowflake CLI 0 ~ 3.27.0 -
Snowflake Snowflake CLI 0 ~ 3.27.0 -

II. Public POCs for CVE-2026-92903

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-92903

登录查看更多情报信息。

Vendor Pages for CVE-2026-92903 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92903

No comments yet


Leave a comment