Echo: snowflake-sqlalchemy: security update to 1.11.0

high Tenable Self-Hosted Container Security Plugin ID 461796

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including:
Improper handling of user-supplied column identifiers in merge operations could allow SQL injection
through attacker-controlled input keys. An attacker may be able to exploit this through request field
names in a dynamic upsert endpoint, potentially enabling read access to data visible to the application's
database role or modification of values within the same MERGE statement. Improper literal rendering of
bound parameters when building certain Snowflake-specific table creation queries could allow SQL
injection. An attacker may be able to exploit this by supplying a crafted string to any application
endpoint that passes user-controlled data through the affected query-building API, potentially causing
arbitrary data exfiltration within the scope of the connection role. Improper forwarding of connection
configuration parameters could allow an attacker to cause the library to read arbitrary local files and
transmit their contents to an attacker-controlled endpoint. An attacker may be able to exploit this in
deployment environments that accept user-controlled connection parameters, potentially exposing sensitive
files accessible to the application process. The fix is available in Snowflake SQLAlchemy version 1.11.0.
Users must manually upgrade. (CVE-2026-15736)

Solution

Update the snowflake-sqlalchemy library and its related packages to version 1.11.0 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-15736

Plugin Details

Severity: High

ID: 461796

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/3/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.5

Percentile: 57.61

CVSS v2

Risk Factor: High

Base Score: 8.7

Temporal Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:P

CVSS Score Source: CVE-2026-15736

CVSS v3

Risk Factor: High

Base Score: 8.3

Temporal Score: 7.2

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/5/2026

Vulnerability Publication Date: 7/14/2026

Reference Information

CVE: CVE-2026-15736