Executive brief
Snowflake's cloud identity drivers fail to validate that authentication requests are sent to legitimate Snowflake endpoints. An attacker who gains control over connection configuration can trick the driver into sending cloud credentials (workload identity tokens) to attacker-controlled hosts. On Azure, this can also expose access tokens scoped to non-Snowflake resources. The vulnerability allows token capture and replay, potentially compromising cloud workload identities and accessing resources they have permission to reach.
Technical details
The vulnerability is a token leakage issue in Snowflake drivers that support WORKLOAD_IDENTITY authentication. The root cause is insufficient host validation: when requesting cloud workload-identity tokens during login, the driver does not verify that the configured host is a legitimate Snowflake endpoint. An attacker with control over connection configuration can redirect token requests to an attacker-controlled host, capturing fresh attestation tokens. The captured tokens can be replayed against Snowflake for their remaining lifetime if the associated workload identity is registered in the target account. On Azure, the token audience is also sourced from connection configuration, allowing an attacker to request managed identity tokens scoped to arbitrary Azure resources. Exploitation requires the application to use WORKLOAD_IDENTITY authentication and already possess an ambient cloud identity. Patched versions restrict the authenticator to recognized Snowflake hosts; users must manually upgrade.
Affected products
- Snowflake Python Driver versions prior to patched release
- Snowflake Go Driver versions prior to patched release
- Snowflake Drivers (general) all drivers with WORKLOAD_IDENTITY support prior to patched release
Timeline
- 2026-09-08: disclosed: CVE-2026-86600 publicly disclosed