Vulnerability Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the downstream PostgreSQL server using credentials explicitly provided by the user with specific pg_execute_server_program permission, exploiting a feature that was wrongly reported as CVE-2019-9193 in PostgreSQL (https://www.postgresql.org/about/news/cve-2019-9193-not-a-security-vulnerability-1935/).
FAQ
What is CVE-2026-51992?
CVE-2026-51992 is a documented vulnerability. Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute ...
How severe is CVE-2026-51992?
CVSS scoring is not yet available for CVE-2026-51992. Check NVD for updates.
Is there a patch for CVE-2026-51992?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.