VAITP Dataset

← Back to the dataset

CVE-2026-86597

Sensitive credentials (tokens, keys, URLs, SAML) logged by Snowflake drivers, exposing them to attackers with log read access.

  • CVSS 6.5
  • 532
  • Information Leakage
  • Remote

Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs, and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction did not cover all affected log paths and data types. An attacker with read access to the log destination, whether the local filesystem, a log aggregation service, or a CI/CD artifact store, could obtain credentials and decryption keys that, if still valid at the time of access, could be used to authenticate to the corresponding Snowflake account or cloud-storage object. Successful exploitation requires read access to the log destination, and impact is bounded by credential lifetime and object scope. The fix is available in Snowflake Connector for Python v4.7.3, Snowflake Go Driver v2.2.0, Snowflake JDBC Driver v4.3.4 (including the snowflake-jdbc-fips and snowflake-jdbc-thin), Snowflake Node.js Driver v3.3.0, Snowflake PHP PDO Driver v4.2.0, and Snowflake ODBC Driver v3.20.0. Users must manually upgrade and should securely delete previously generated diagnostic logs containing sensitive information where retention is not required.

CWE
532
CVSS base score
6.5
Published
2026-09-08
OWASP
A09 Security Logging and Monitoring Failures
Orthogonal defect classification
Interface
Code defect classification
Missing Check
Category
Information Leakage
Subcategory
Insecure Handling of Sensitive Data
Accessibility scope
Remote
Impact
Information Disclosure
Fixed by upgrading
Yes

Solution

Upgrade to the patched versions: Python Connector v4.7.3; Go Driver v2.2.0; JDBC Driver v4.3.4 (including snowflake‑jdbc‑fips and snowflake‑jdbc‑thin); Node.js Driver v3.3.0; PHP PDO Driver v4.2.0; ODBC Driver v3.20.0.

Vulnerable code sample

import logging
import snowflake.connector

logger = logging.getLogger("snowflake.connector")
logger.setLevel(logging.INFO)

def run_query():
    # VULNERABLE: logs authentication token to diagnostic log
    ctx = snowflake.connector.connect(
        user="my_user",
        password="my_password",
        account="my_account"
    )
    logger.info(f"Authenticated with token: {ctx.session_token}")
    cs = ctx.cursor()
    cs.execute("SELECT CURRENT_VERSION()")
    result = cs.fetchone()
    cs.close()
    ctx.close()
    return result

Patched code sample

import logging
import snowflake.connector

logger = logging.getLogger("snowflake.connector")
logger.setLevel(logging.INFO)

def run_query():
    # FIX: remove logging of authentication token
    ctx = snowflake.connector.connect(
        user="my_user",
        password="my_password",
        account="my_account"
    )
    # No sensitive data logged here
    cs = ctx.cursor()
    cs.execute("SELECT CURRENT_VERSION()")
    result = cs.fetchone()
    cs.close()
    ctx.close()
    return result

Cite this entry

@misc{vaitp:cve202686597,
  title        = {{Sensitive credentials (tokens, keys, URLs, SAML) logged by Snowflake drivers, exposing them to attackers with log read access.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-86597},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-86597/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::