CVE-2026-15067Patch

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection via an unsanitized data source input could result in arbitrary SQL execution under the provider's privileged Snowflake session, potentially enabling sensitive data exfiltration and minting of long-lived access credentials. Exploitation requires the ability for an attacker to influence a workspace variable in a pipeline where this data source was enabled. Improper neutralization of identifier content in user resource inputs could allow DDL injection into user management statements, potentially causing accounts to be created with attacker-controlled credentials and without the security controls configured by the operator. The fix is available in Snowflake Terraform Provider version 2.18.0. Users must manually upgrade.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-08: 1Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - Snowflake Terraform Provider SQL injection enables arbitrary SQL under privileged session (CVE-2026-15067) Snowflake Terraform Provider contains an injection flaw in a data source where user-controlled input is passed into Snowflake queries without proper sanitization/escaping. The root cause is improper input validation and identifier neutralization, resulting in SQL injection/DDL injection in provider-generated statements (including user management DDL). An attacker who can influence Terraform workspace variables (e.g., CI/CD pipeline variables) when the vulnerable data source is enabled can inject SQL through the provider’s privileged Snowflake session without needing direct Snowflake credentials. Successful exploitation enables arbitrary SQL execution leading to sensitive data exfiltration, creation of attacker-controlled users/credentials (potentially long-lived), and broader account compromise. 👉 Affected: terraform-provider-snowflake < 2.18.0 | Upgrade to 2.18.0

    Post summary

    The breach is a SQL injection in the Snowflake Terraform provider; a patch (v2.18.0) is available and the post details the technical flaw.

    0000073
    246 followersView on X

Explore more