CVE-2026-86597
Sensitive credentials (tokens, keys, URLs, SAML) logged by Snowflake drivers, exposing them to attackers with log read access.
- CVSS 6.5
- 532
- Information Leakage
- Remote
Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did not cover all affected log paths and data types. An attacker with read access to the log destination, whether the local filesystem, a log aggregation service, or a CI/CD artifact store, could obtain credentials and decryption keys that, if still valid at the time of access, could be used to authenticate to the corresponding Snowflake account or cloud-storage object. Successful exploitation requires read access to the log destination, and impact is bounded by credential lifetime and object scope. The fix is available in Snowflake Connector for Python v4.7.3, Snowflake Go Driver v2.2.0, Snowflake JDBC Driver v4.3.4 (including the snowflake-jdbc-fips and snowflake-jdbc-thin), Snowflake Node.js Driver v3.3.0, Snowflake PHP PDO Driver v4.2.0, and Snowflake ODBC Driver v3.20.0. Users must manually upgrade and should securely delete previously generated diagnostic logs containing sensitive information where retention is not required.
- CWE
- 532
- CVSS base score
- 6.5
- Published
- 2026-09-08
- OWASP
- A09 Security Logging and Monitoring Failures
- Orthogonal defect classification
- Interface
- Code defect classification
- Missing Check
- Category
- Information Leakage
- Subcategory
- Insecure Handling of Sensitive Data
- Accessibility scope
- Remote
- Impact
- Information Disclosure
- Fixed by upgrading
- Yes
Solution
Upgrade to the patched versions: Python Connector v4.7.3; Go Driver v2.2.0; JDBC Driver v4.3.4 (including snowflake‑jdbc‑fips and snowflake‑jdbc‑thin); Node.js Driver v3.3.0; PHP PDO Driver v4.2.0; ODBC Driver v3.20.0.
Vulnerable code sample
import logging
import snowflake.connector
logger = logging.getLogger("snowflake.connector")
logger.setLevel(logging.INFO)
def run_query():
# VULNERABLE: logs authentication token to diagnostic log
ctx = snowflake.connector.connect(
user="my_user",
password="my_password",
account="my_account"
)
logger.info(f"Authenticated with token: {ctx.session_token}")
cs = ctx.cursor()
cs.execute("SELECT CURRENT_VERSION()")
result = cs.fetchone()
cs.close()
ctx.close()
return resultPatched code sample
import logging
import snowflake.connector
logger = logging.getLogger("snowflake.connector")
logger.setLevel(logging.INFO)
def run_query():
# FIX: remove logging of authentication token
ctx = snowflake.connector.connect(
user="my_user",
password="my_password",
account="my_account"
)
# No sensitive data logged here
cs = ctx.cursor()
cs.execute("SELECT CURRENT_VERSION()")
result = cs.fetchone()
cs.close()
ctx.close()
return resultCite this entry
@misc{vaitp:cve202686597,
title = {{Sensitive credentials (tokens, keys, URLs, SAML) logged by Snowflake drivers, exposing them to attackers with log read access.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-86597},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-86597/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
