Junglewise Threat Intelligence

CVE-2026-13750: Snowflake CLI sensitive information disclosure in local logs

CVE-2026-13750 · Severity: medium · CVSS 5.5 · Published 2026-06-29

Technologies: Snowflake CLI. Vendors: Snowflake.

Executive brief

The Snowflake Command Line Interface (CLI) contained a flaw that caused sensitive information, including passwords and private keys, to be saved in plain text within local log files. If an unauthorized person or malicious software gains access to a user's computer, they could read these logs to steal credentials and access the user's Snowflake account. This issue affects users who have debug logging enabled and requires a manual update to the software to resolve.

Technical details

A vulnerability in Snowflake CLI (versions 3.0.0 through 3.18.x) involves the improper handling of sensitive information (CWE-532), where plaintext credentials are written to persistent local debug logs. The root cause is the insertion of sensitive connection context data—including passwords, tokens, and private key material—into the application's logging output without adequate masking. An attacker requires local read access to the affected user's filesystem to retrieve these logs. Successful exploitation allows for credential theft and subsequent unauthorized access to Snowflake resources. The vulnerability is mitigated in version 3.19, which requires a manual upgrade by the user.

Affected products

  • Snowflake Snowflake CLI 3.0.0 to 3.18.x

Timeline

  • 2026-06-29: advisory: Initial advisory published by Snowflake and NVD

References

Related threats