A vulnerability classified as critical has been found in ClickHouse Server up to 26.3.9.8. The impacted element is the function create dictionaries of the component Create Dictionaries. The manipulation leads to sql injection.

This vulnerability is referenced as CVE-2026-51992. Remote exploitation of the attack is possible. No exploit is available.