CVE-2026-16870: Multiple Security Vulnerabilities in Snowflake libsnowflakeclient

Published Jul 24, 2026
·
Updated

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim process later downloads, and impact would be limited to deployments where principals with different privilege levels share the same internal stage. A related out-of-bounds write in the same download path could allow memory corruption with attacker-controlled write primitives. An attacker may exploit this through a crafted initialization vector metadata field on a shared stage, and impact would be limited by the same stage-write precondition. Improper validation of connection parameters could allow an attacker-controlled input to redirect outbound authentication requests — including credentials and tokens — to an attacker-controlled endpoint. Impact is limited to embedding deployments where a lower-privileged principal can influence connection configuration while higher-privileged service credentials are in use. The fix is available in Snowflake libsnowflakeclient version 2.9.2. The Snowflake PHP PDO Driver and Snowflake ODBC Driver embed the affected library; fixes are available in versions 4.1.0 and 3.19.0 respectively. Users must manually upgrade.

Affected Software

3 affected components
Snowflake libsnowflakeclient<2.9.2
Snowflake PHP PDO Driver<4.1.0
Snowflake ODBC Driver<3.19.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Snowflake libsnowflakeclient to a version that resolves this vulnerability.

    Fixed in 2.9.2
  2. Upgrade

    Upgrade Snowflake PHP PDO Driver to a version that resolves this vulnerability.

    Fixed in 4.1.0
  3. Upgrade

    Upgrade Snowflake ODBC Driver to a version that resolves this vulnerability.

    Fixed in 3.19.0

Event History

Jul 24, 2026
CVE Published
via MITRE·04:40 AM
Data Sourced
via MITRE·04:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-16870?

The severity of CVE-2026-16870 is rated high with a score of 8.8.

2

How do I fix CVE-2026-16870?

To fix CVE-2026-16870, upgrade Snowflake libsnowflakeclient to version 2.9.2 or later.

3

What vulnerabilities are associated with CVE-2026-16870?

CVE-2026-16870 includes vulnerabilities such as stack-based buffer overflow and potential remote code execution.

4

What can attackers do with CVE-2026-16870?

Attackers can exploit CVE-2026-16870 to achieve remote code execution and exfiltrate credentials.

5

Which versions of Snowflake libsnowflakeclient are affected by CVE-2026-16870?

Versions of Snowflake libsnowflakeclient prior to 2.9.2 are affected by CVE-2026-16870.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203