PT-2026-49302 · Clickhouse+1 · Clickhouse+1

·

CVE-2026-39196

·

Published

2026-06-15

·

Updated

2026-06-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vector versions prior to 0.55.0
Description The ClickHouse sink contains a SQL/identifier injection flaw. The software escaped the table identifier but interpolated the database value raw into the INSERT statement, allowing a crafted database value to break out of identifier quoting. This occurs in the KeyPartitioner::partition() function via the set uri query parameter, which could allow attackers to access sensitive database information using crafted SQL statements.
Recommendations Update to version 0.55.0.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39196

Affected Products

Clickhouse
Vector