CVE-2026-51992

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the downstream PostgreSQL server using credentials explicitly provided by the user with specific pg_execute_server_program permission, exploiting a feature that was wrongly reported as CVE-2019-9193 in PostgreSQL (https://www.postgresql.org/about/news/cve-2019-9193-not-a-security-vulnerability-1935/).
CVSS

No CVSS.

References

No reference.

Configurations

No configuration.

History

No history.

Information

Published : 2026-07-29 17:16

Updated : 2026-08-06 09:16


NVD link : CVE-2026-51992

Mitre link : CVE-2026-51992

CVE.ORG link : CVE-2026-51992


JSON object : View

Products Affected

No product.

CWE

No CWE.