This CVE has been withdrawn by MITRE
MITRE marked CVE-2026-51992 as REJECTED on . There is no longer a valid blast radius to assess. Any historical package or vendor data shown below is preserved for audit reference only.
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the downstream PostgreSQL server using credentials explicitly provided by the user with specific pg_execute_server_program permission, exploiting a feature that was wrongly reported as CVE-2019-9193 in…
CVE-2026-51992 Blast Radius
✕ WITHDRAWN — HISTORICAL DATASQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries f…