
🚨 HIGH - Snowflake Terraform Provider SQL injection enables arbitrary SQL under privileged session (CVE-2026-15067) Snowflake Terraform Provider contains an injection flaw in a data source where user-controlled input is passed into Snowflake queries without proper sanitization/escaping. The root cause is improper input validation and identifier neutralization, resulting in SQL injection/DDL injection in provider-generated statements (including user management DDL). An attacker who can influence Terraform workspace variables (e.g., CI/CD pipeline variables) when the vulnerable data source is enabled can inject SQL through the provider’s privileged Snowflake session without needing direct Snowflake credentials. Successful exploitation enables arbitrary SQL execution leading to sensitive data exfiltration, creation of attacker-controlled users/credentials (potentially long-lived), and broader account compromise. 👉 Affected: terraform-provider-snowflake < 2.18.0 | Upgrade to 2.18.0
Post summary
The breach is a SQL injection in the Snowflake Terraform provider; a patch (v2.18.0) is available and the post details the technical flaw.
