CVE-2026-15062Patch

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege users to execute SQL beyond their authorization scope. An attacker could exploit these vulnerabilities by embedding SQL payloads in source database column names to escalate privileges via the DataFrameReader.dbapi() API by supplying a specially crafted location parameter to DataFrameWriter write methods to redirect a COPY INTO to an arbitrary source query, or by including a backslash-single-quote sequence in an export path to defeat the normalize_path() sanitizer and inject SQL via DataFrame.to_csv(). Successful exploitation may result in source database compromise, unauthorized cross-tenant data exfiltration, or unauthorized read of Snowflake account data.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CRITICAL - Snowpark Python SDK SQL Injection Authorization Bypass (CVE-2026-15062) CVE-2026-15062 is a SQL injection flaw in the Snowflake Snowpark Python SDK (snowpark-python) that lets authenticated low-privilege users run SQL beyond their intended authorization scope. The root cause is improper input validation/escaping of attacker-controlled identifiers and parameters (SQLi), including path normalization bypass in normalize_path() used by http://DataFrame.to_csv(). Exploitation is possible by embedding malicious SQL in source database column names, crafting parameters passed to DataFrameReader.dbapi() and DataFrameWriter write methods, or abusing the to_csv() path handling to inject SQL, requiring only valid low-privileged credentials in a Snowpark-enabled environment. Impact includes unauthorized query execution, source database compromise, cross-tenant data exfiltration, and unauthorized access to Snowflake account data. 👉 Affected: snowpark-python < 1.53.0 | Upgrade to 1.53.0

    Post summary

    The tweet discloses a critical SQL injection flaw (CVE‑2026‑15062) in Snowpark Python SDK that lets low‑privilege users execute arbitrary SQL, emphasizing the need to upgrade to version 1.53.0.

    0000084
    246 followersView on X

Explore more