CVE-2026-51992: SQL Injection
Published Jul 29, 2026
·Updated
SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function.
Affected Software
1 affected component
Clickhouse ClickHouse Server<=26.3.9.8
Event History
Jul 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-51992?
CVE-2026-51992 has a critical severity rating of 9.1.
2
How do I fix CVE-2026-51992?
To fix CVE-2026-51992, upgrade to ClickHouse Server version 26.3.9.9 or later.
3
What type of vulnerability is CVE-2026-51992?
CVE-2026-51992 is an SQL Injection vulnerability.
4
What can be exploited in CVE-2026-51992?
CVE-2026-51992 allows a remote attacker to execute arbitrary code via the create dictionaries function.
5
Which versions of ClickHouse Server are affected by CVE-2026-51992?
ClickHouse Server versions less than or equal to 26.3.9.8 are affected by CVE-2026-51992.