CVE-2026-51992

UnknownEPSS 0.52%

Last modified

This CVE is reserved or rejected; no details have been published by NVD.

Description

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. ClickHouse's PostgreSQL integration intentionally allows users with valid PostgreSQL credentials to execute queries against a remote PostgreSQL server. No vulnerability in ClickHouse is exploited; code execution occurs on the downstream PostgreSQL server using credentials explicitly provided by the user with specific pg_execute_server_program permission, exploiting a feature that was wrongly reported as CVE-2019-9193 in PostgreSQL (https://www.postgresql.org/about/news/cve-2019-9193-not-a-security-vulnerability-1935/).

Metrics

EPSS Probability
0.52%

41.0th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
——n/a

Timeline

Published
Last Modified
Status
Rejected

Related CVEs from 2026

Are you affected by CVE-2026-51992?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST