Snowflake Vulnerabilities and Affected Products
Vulnerabilities associated with Snowflake SQLAlchemy.
Products
Clear product- Snowflake CLI7 vulnerabilities
- Cortex Code CLI1 vulnerability
- Snowflake Connector for Python1 vulnerability
- Snowflake libsnowflakeclient1 vulnerability
- Snowflake ODBC1 vulnerability
- Snowflake ODBC Driver1 vulnerability
- Snowflake PHP PDO Driver1 vulnerability
- Snowflake Python APIs1 vulnerability
- Snowflake Spark Connector1 vulnerability
- Snowflake SQLAlchemy1 vulnerability
- snowflake_jdbc1 vulnerability
- Snowpark Python SDK1 vulnerability
- Terraform Provider for Snowflake1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-15736HIGH | Multiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemySnowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. An attacker may be able to exploit this through request field names in a dynamic upsert endpoint, potentially enabling read access to data visible to the application's database role or modification of values within the same MERGE statement. Improper literal ren… | CVSS8.3v3.1 | EPSS0.267% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |