CVE-2026-15183: Input Validation Vulnerabilities in Snowflake Spark Connector

Published Jul 14, 2026
·
Updated

Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL with the connector's Snowflake role, or redirect COPY operations to attacker-controlled storage. An attacker could exploit these vulnerabilities by supplying a crafted OAuth token request URL, placing malicious files in an ingestion pipeline, injecting SQL via staging options in a shared Spark environment , or issuing runtime SET commands in a shared Spark-SQL session to inject arbitrary SQL into the SnowflakeFallbackCatalog's option map, which executes under the cluster admin's JDBC credentials. Successful exploitation may result in credential theft, unauthorized access to Snowflake account data, or privilege escalation within connected infrastructure.

Affected Software

2 affected components
Snowflake Snowflake Spark Connector<3.2.1
spark-snowflake<3.2.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade spark-snowflake to a version that resolves this vulnerability.

    Fixed in 3.2.1
  2. Compensating control

    If you must use a vulnerable spark-snowflake version, restrict which users/jobs can submit crafted OAuth token request URLs and limit outbound access so OAuth client credentials and COPY destinations cannot be redirected to attacker-controlled endpoints.

  3. Compensating control

    In shared Spark and Spark-SQL environments, prevent untrusted users from creating or issuing runtime SQL/SET commands in shared Spark-SQL sessions that could inject arbitrary SQL into SnowflakeFallbackCatalog's option map under cluster admin JDBC credentials.

  4. Operational

    Rotate any Snowflake OAuth client credentials (and any connector-related secrets) that may have been exposed via exfiltration of OAuth client credentials from successful exploitation.

Event History

Jul 14, 2026
CVE Published
via MITRE·08:42 AM
Data Sourced
via MITRE·08:42 AM
DescriptionWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-15183?

CVE-2026-15183 has a critical severity rating of 9.2.

2

What types of vulnerabilities are present in CVE-2026-15183?

CVE-2026-15183 includes multiple input validation vulnerabilities related to SQL Injection and SSRF.

3

How do I fix CVE-2026-15183?

To mitigate CVE-2026-15183, upgrade to the Snowflake Spark Connector version 3.2.1 or later.

4

What impact can CVE-2026-15183 have on my system?

CVE-2026-15183 can lead to exfiltration of OAuth client credentials and unauthorized execution of SQL queries.

5

Is my Snowflake Spark Connector affected by CVE-2026-15183?

Versions of the Snowflake Spark Connector prior to 3.2.1 are affected by CVE-2026-15183.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203