CVE-2026-86597
Awaiting Analysis Awaiting Analysis - Queue

Sensitive Information Logged in Snowflake Drivers

Vulnerability report for CVE-2026-86597, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-10

Assigner: SNOWFLAKE

Description

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did not cover all affected log paths and data types. An attacker with read access to the log destination, whether the local filesystem, a log aggregation service, or a CI/CD artifact store, could obtain credentials and decryption keys that, if still valid at the time of access, could be used to authenticate to the corresponding Snowflake account or cloud-storage object. Successful exploitation requires read access to the log destination, and impact is bounded by credential lifetime and object scope. The fix is available in Snowflake Connector for Python v4.7.3, Snowflake Go Driver v2.2.0, Snowflake JDBC Driver v4.3.4 (including the snowflake-jdbc-fips and snowflake-jdbc-thin), Snowflake Node.js Driver v3.3.0, Snowflake PHP PDO Driver v4.2.0, and Snowflake ODBC Driver v3.20.0. Users must manually upgrade and should securely delete previously generated diagnostic logs containing sensitive information where retention is not required.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-10
Generated
2026-09-28
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
snowflake snowflake_python *
snowflake snowflake_go *
snowflake snowflake_jdbc *
snowflake snowflake_node.js *
snowflake snowflake_php_pdo *
snowflake snowflake_odbc *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves sensitive information like authentication tokens, encryption keys, and SAML assertions being logged in diagnostic logs by Snowflake drivers. The issue occurs when log redaction fails to cover all affected log paths, allowing attackers with read access to logs to steal credentials and decryption keys.

Detection Guidance

Check diagnostic logs for exposed sensitive data like authentication tokens, encryption keys, or SAML assertions. Search logs for patterns matching credentials or cloud-storage URLs. Review logs in filesystem, log aggregation services, or CI/CD artifact stores for any of the affected drivers.

Impact Analysis

An attacker could gain access to your Snowflake account or cloud-storage objects if they read the logs containing valid credentials. The impact depends on credential lifetime and object scope, but could lead to unauthorized data access or manipulation.

Compliance Impact

This vulnerability could violate compliance requirements by exposing sensitive data in logs, such as personally identifiable information or protected health information. Organizations may face penalties for failing to protect such data under regulations like GDPR or HIPAA.

Mitigation Strategies

Upgrade to the patched versions of the affected Snowflake drivers immediately. Securely delete any previously generated diagnostic logs containing sensitive information if retention is not required. Ensure log redaction covers all affected paths and data types in future logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86597. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart