Junglewise Threat Intelligence

CVE-2026-15183: Snowflake Spark Connector multiple input validation vulnerabilities

CVE-2026-15183 · Severity: info · CVSS 9.2 · Published 2026-07-14

Vendors: Snowflake.

Executive brief

The Snowflake Spark Connector, used to connect Apache Spark data processing environments to Snowflake databases, contains multiple security flaws. These vulnerabilities could allow an attacker to steal login credentials, run unauthorized database commands, or redirect data to their own storage. This could lead to the theft of sensitive corporate data or unauthorized access to the broader Snowflake environment.

Technical details

The Snowflake Spark Connector (spark-snowflake) prior to version 3.2.1 is affected by multiple input validation flaws including SQL Injection (CWE-89), Server-Side Request Forgery (CWE-918), and Confused Deputy (CWE-441) vulnerabilities. Attackers can exploit these by crafting malicious OAuth token request URLs, injecting SQL via staging options in shared Spark environments, or using runtime SET commands to override trusted catalog connection options. Successful exploitation allows for the exfiltration of OAuth client credentials, execution of arbitrary SQL under the connector's role, or redirection of COPY operations to attacker-controlled storage. The issues were addressed in version 3.2.1 by restricting the fallback catalog to immutable configurations, improving identifier quoting, and adding URL scheme/host validation.

Affected products

  • Snowflake Snowflake Spark Connector (spark-snowflake) < 3.2.1

Timeline

  • 2026-07-08: patched: Version 3.2.1 released
  • 2026-07-14: advisory: NVD publication date

References