OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-51992

UNKNOWN · CVSS N/A Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

A critical SQL Injection vulnerability in ClickHouse Server versions up to 26.3.9.8 allows remote attackers to execute arbitrary code through the create dictionaries function. This poses a significant risk to any organization using affected versions, as it could lead to unauthorized access and control over the database server. Organizations operating ClickHouse should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51992
Severity
UNKNOWN
CVSS
N/A
EPSS
N/A

Original NVD Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the downstream PostgreSQL server using credentials explicitly provided by the user with specific pg_execute_server_program permission, exploiting a feature that was wrongly reported as CVE-2019-9193 in PostgreSQL (https://www.postgresql.org/about/news/cve-2019-9193-not-a-security-vulnerability-1935/).