


Perceptive Security
SOC/SIEM Consultancy

SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function.
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 20:03:55
Source:
nvd.nist.gov
Database & Storage, Zero-Day Vulnerabilities, Web Technologies
A SQL Injection vulnerability has been identified in ClickHouse Server versions 26.3.9.8 and below. The flaw resides in the 'create dictionaries' function, which can be exploited by a remote attacker without authentication. Successful exploitation allows arbitrary code execution on the affected server. The vulnerability is tracked as CVE-2026-51992 and has been published on the NVD. A proof-of-concept exploit has been published on GitHub by TheLiimbo. The affected product is ClickHouse, a popular open-source columnar database management system. Users are advised to update to a patched version as soon as one becomes available. The criticality is rated High due to the potential for remote code execution.
Technical details
Mitigation steps:
Affected products:
ClickHouse Server <= 26.3.9.8
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51992
https://clickhouse.com/docs/sql-reference/dictionaries#postgresql
https://github.com/TheLiimbo/CVE-2026-51992
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
