Description
Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries. An attacker who is able to supply a malicious project configuration file or craft command-line input can cause Snowflake CLI to execute attacker-controlled SQL statements in the context of the victim's Snowflake session and active role. Successful exploitation requires either write or pull-request access to a project repository whose CI/CD pipeline runs Snowflake CLI under an elevated service account role, or the ability to supply untrusted input to CLI-wrapping automation. Impact is limited by the privileges held by the configured Snowflake role at execution time. The fix is available in Snowflake CLI version 3.27.0, which also addresses several additional security findings. Users must manually upgrade.
Published: 2026-09-17
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection
Action: Apply patch
AI Analysis

Impact

The Snowflake CLI prior to version 3.27.0 fails to properly validate user‑supplied values, allowing these values to be interpolated into SQL strings that the CLI executes as multi‑statement queries. This is a classic SQL injection vulnerability (CWE‑89) that can give an attacker the ability to execute arbitrary SQL commands within the Snowflake session and the role that the CLI is running under. Depending on the privileges of that role, the attacker may read, modify, or delete data and alter Snowflake objects.

Affected Systems

All users of Snowflake’s command‑line interface who are running a version older than 3.27.0 are affected. The affected product is the Snowflake CLI, and the vendor is Snowflake. No narrower version range is specified beyond the pre‑3.27.0 statement.

Risk and Exploitability

The base CVSS score of 8.2 represents a high severity. No EPSS score is available, so the current exploitation likelihood is not quantified, but the absence of a low EPSS does not reduce the inherent risk. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation has been reported. Attackers must obtain control over a project configuration file or inject malicious values via command‑line arguments in a CI/CD pipeline that runs Snowflake CLI with an elevated service‑account role. Successful exploitation therefore requires either write or pull‑request access to a project repository with such a pipeline, or the ability to supply untrusted input to automation that invokes the CLI. Thus the attack vector is oriented toward internal development or integration environments rather than direct external network exposure.

Generated by OpenCVE AI on September 18, 2026 at 06:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Snowflake CLI to version 3.27.0 or later.
  • Verify and sanitize all project configuration files that the CLI consumes, ensuring they originate from trusted sources.
  • Restrict write and pull‑request permissions to the project repository and enforce least privilege on the service account role used by CI/CD pipelines.

Generated by OpenCVE AI on September 18, 2026 at 06:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Snowflake
Snowflake snowflake Cli
Vendors & Products Snowflake
Snowflake snowflake Cli

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries. An attacker who is able to supply a malicious project configuration file or craft command-line input can cause Snowflake CLI to execute attacker-controlled SQL statements in the context of the victim's Snowflake session and active role. Successful exploitation requires either write or pull-request access to a project repository whose CI/CD pipeline runs Snowflake CLI under an elevated service account role, or the ability to supply untrusted input to CLI-wrapping automation. Impact is limited by the privileges held by the configured Snowflake role at execution time. The fix is available in Snowflake CLI version 3.27.0, which also addresses several additional security findings. Users must manually upgrade.
Title Improper Input Validation in Snowflake CLI Versions Allow Unsanitized User-Controlled Values to be Interpolated into SQL Strings
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Snowflake Snowflake Cli
cve-icon MITRE

Status: PUBLISHED

Assigner: SNOWFLAKE

Published:

Updated: 2026-09-17T12:08:06.777Z

Reserved: 2026-09-17T10:29:18.996Z

Link: CVE-2026-92903

cve-icon Vulnrichment

Updated: 2026-09-17T12:08:02.675Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T11:17:03.460

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-92903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:00:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')