Back

MEDIUM

Snowflake JDBC Driver auto-configuration account validation permits credential redirection

Published Sep 4, 2026

Description

Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to be redirected to an attacker-selected HTTPS endpoint. An attacker able to control the account value could cause the driver to transmit a reusable login credential to a host of their choosing and replay it to obtain the privileges granted to that credential. Successful exploitation requires an application using jdbc:snowflake:auto with a connections.toml section that omits an explicit host and a lower-trust principal able to set the account value; ordinary JDBC URLs are unaffected. The fix is available in Snowflake JDBC Driver version 4.3.4, including the snowflake-jdbc-fips and snowflake-jdbc-thin. Users must manually upgrade.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SNOWFLAKE
Published Sep 4, 2026
Updated Sep 10, 2026
Reserved Sep 4, 2026
CISA Vulnrichment
Updated Sep 4, 2026
NVD
Status Awaiting Analysis
Modified Sep 10, 2026
Red Hat
Severity n/a
Public date n/a