SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityRejected

CVE-2026-51992

ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server.

UnscoredEPSS —

Does this matter?

Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.

Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the downstream PostgreSQL server using credentials explicitly provided by the user with specific pg_execute_server_program permission, exploiting a feature that was wrongly reported as CVE-2019-9193 in PostgreSQL (https://www.postgresql.org/about/news/cve-2019-9193-not-a-security-vulnerability-1935/).

CVSS
Not yet scored
EPSS
No score yet
CISA KEV
Not listed
Source
cb7ba516-3b07-4c98-b0c2-715220f1a8f6

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.