CVE-2026-15183
Last modified
CVE-2026-15183 is a critical-severity vulnerability rated 9.2/10 on the CVSS scale. Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL with the connector's Snowflake role, or redirect COPY operations to attacker-controlled storage. An attacker could exploit these vulnerabilities by supplying a crafted OAuth token request URL, placing malicious files in an ingestion pipeline, injecting SQL via staging options in a shared Spark environment , or issuing runtime SET commands in a shared Spark-SQL session to inject arbitrary SQL into the SnowflakeFallbackCatalog's option map, which executes under the cluster admin's JDBC credentials. EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrate OAuth client credentials, execute arbitrary SQL with the connector's Snowflake role, or redirect COPY operations to attacker-controlled storage. An attacker could exploit these vulnerabilities by supplying a crafted OAuth token request URL, placing malicious files in an ingestion pipeline, injecting SQL via staging options in a shared Spark environment , or issuing runtime SET commands in a shared Spark-SQL session to inject arbitrary SQL into the SnowflakeFallbackCatalog's option map, which executes under the cluster admin's JDBC credentials. Successful exploitation may result in credential theft, unauthorized access to Snowflake account data, or privilege escalation within connected infrastructure.
Metrics
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Snowflake | Snowflake Spark Connector | >= 0.1.0, < 3.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-15183?
How severe is CVE-2026-15183?
How do I fix CVE-2026-15183?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-15171SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and…5.5
- CVE-2026-15172FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.…5.5
- CVE-2026-15173pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows …5.5
- CVE-2026-15174Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0…5.5
- CVE-2026-1518Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. After fur…
- CVE-2026-15182A vulnerability has been found in GNU LibreDWG up to 0.13.4.…5.3
- CVE-2026-15184A vulnerability was found in GNU LibreDWG up to 0.13.4. The …3.3
- CVE-2026-15185A vulnerability was determined in GPAC 26.03-DEV. This affec…3.3
- CVE-2026-15186A vulnerability was identified in macrozheng mall up to 1.0.…6.3
- CVE-2026-15187A security flaw has been discovered in enquirer up to 2.4.1.…4.3
- CVE-2026-15188A weakness has been identified in manjurulhoque django-job-p…6.3
- CVE-2026-15189A security vulnerability has been detected in aerostackdev a…6.3
Are you affected by CVE-2026-15183?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
