Vulnerabilidades em Snowflake
15 resultadosAnálise Vexday
Snowflake apresenta 15 vulnerabilidades catalogadas, com concentração preocupante de 13 divulgadas nos últimos 90 dias, indicando exposição recente e contínua. Embora nenhuma esteja sob ataque ativo conhecido (KEV), 3 atingem severidade crítica e a fraqueza dominante é injeção SQL (CWE-89), vetor clássico e potencialmente devastador em contextos de data warehouse. A janela temporal recente sugere paisagem de risco em evolução que demanda monitoramento contínuo e patching prioritário.
CVE-2026-13749HIGHSnowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template InjectionEPSS 0.4%CVE-2026-15067HIGHMultiple Security Vulnerabilities in Terraform Provider for Snowflake Could Allow Privilege Escalation and Unauthorized Snowflake Account TakeoverEPSS 0.4%CVE-2026-16870HIGHMultiple Security Vulnerabilities in Snowflake libsnowflakeclientEPSS 0.4%CVE-2026-6442HIGHImproper Command Detection Logic Allows RCE in Cortex Code Command-Line InterfaceEPSS 0.4%CVE-2026-13744HIGHSnowflake CLI SQL Injection Through Improper Neutralization of User-Controlled InputEPSS 0.3%CVE-2026-15062CRITICALSQL Injection in Snowflake Snowpark Python SDKEPSS 0.3%CVE-2026-15736HIGHMultiple SQL/DDL Injection and Arbitrary File Read Vulnerabilities in snowflake-sqlalchemyEPSS 0.3%CVE-2026-15183CRITICALInput Validation Vulnerabilities in Snowflake Spark ConnectorEPSS 0.2%CVE-2026-13752MEDIUMSnowflake CLI SQL Injection Through Improper Neutralization of Parameters in Secret Creation and SPCS Service Log CommandsEPSS 0.2%CVE-2026-15925CRITICALImproper TLS Hostname Verification in Snowflake Connector for PythonEPSS 0.2%CVE-2025-46614LOWIn Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, aka Insertion of SensEPSS 0.1%CVE-2026-13748MEDIUMSnowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path RestrictionEPSS 0.1%CVE-2026-13746LOWSnowflake CLI SQL Injection Through Improper Neutralization of Local CLI ParametersEPSS 0.1%CVE-2026-13751MEDIUMSnowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!loadEPSS 0.1%CVE-2026-13750MEDIUMSnowflake CLI Sensitive Credential Exposure Through Debug LoggingEPSS 0.1%