CVE-2026-51992: SQL Injection
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the downstream PostgreSQL server using credentials explicitly provided by the user with specific pgexecuteserverprogram permission, exploiting a feature that was wrongly reported as CVE-2019-9193 in PostgreSQL (https://www.postgresql.org/about/news/cve-2019-9193-not-a-security-vulnerability-1935/).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ClickHouseto a version that resolves this vulnerability.Fixed in 26.3.9.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-51992?
CVE-2026-51992 has a critical severity rating of 9.1.
How do I fix CVE-2026-51992?
To fix CVE-2026-51992, upgrade to ClickHouse Server version 26.3.9.9 or later.
What type of vulnerability is CVE-2026-51992?
CVE-2026-51992 is an SQL Injection vulnerability.
What can be exploited in CVE-2026-51992?
CVE-2026-51992 allows a remote attacker to execute arbitrary code via the create dictionaries function.
Which versions of ClickHouse Server are affected by CVE-2026-51992?
ClickHouse Server versions less than or equal to 26.3.9.8 are affected by CVE-2026-51992.