Description
There are packages installed that are affected by a vulnerability referenced in the following CVE:
- Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and
ODBC drivers allowed authentication tokens, query-result encryption keys, pre-signed cloud-storage URLs,
and SAML assertions to be written to diagnostic logs in circumstances where the available log redaction
did not cover all affected log paths and data types. An attacker with read access to the log destination,
whether the local filesystem, a log aggregation service, or a CI/CD artifact store, could obtain
credentials and decryption keys that, if still valid at the time of access, could be used to authenticate
to the corresponding Snowflake account or cloud-storage object. Successful exploitation requires read
access to the log destination, and impact is bounded by credential lifetime and object scope. The fix is
available in Snowflake Connector for Python v4.7.3, Snowflake Go Driver v2.2.0, Snowflake JDBC Driver
v4.3.4 (including the snowflake-jdbc-fips and snowflake-jdbc-thin), Snowflake Node.js Driver v3.3.0,
Snowflake PHP PDO Driver v4.2.0, and Snowflake ODBC Driver v3.20.0. Users must manually upgrade and should
securely delete previously generated diagnostic logs containing sensitive information where retention is
not required. (CVE-2026-86597)
Solution
Update the google-cloud-otel-ops-collector library and its related packages to version 0.160.0-r1 or later.
Plugin Details
Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security
Risk Information
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:N/A:N
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 9/8/2026