Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 06 Aug 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function. | This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the downstream PostgreSQL server using credentials explicitly provided by the user with specific pg_execute_server_program permission, exploiting a feature that was wrongly reported as CVE-2019-9193 in PostgreSQL (https://www.postgresql.org/about/news/cve-2019-9193-not-a-security-vulnerability-1935/). |
Thu, 06 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ClickHouse Server: ClickHouse Server: Arbitrary code execution via SQL Injection in create dictionaries function | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 04 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ClickHouse Server SQL Injection via Create Dictionaries Function |
Sat, 01 Aug 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ClickHouse Server SQL Injection via Create Dictionaries Function |
Wed, 29 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Wed, 29 Jul 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Clickhouse
Clickhouse clickhouse |
|
| Vendors & Products |
Clickhouse
Clickhouse clickhouse |
Wed, 29 Jul 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function. | |
| References |
|
Status: REJECTED
Assigner: mitre
Published:
Updated: 2026-08-06T08:43:08.121Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-51992
Updated: 2026-07-29T18:11:10.351Z
Status : Rejected
Published: 2026-07-29T17:16:52.040
Modified: 2026-08-06T09:16:36.693
Link: CVE-2026-51992
OpenCVE Enrichment
Updated: 2026-08-04T12:45:05Z