SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries function.
https://github.com/TheLiimbo/CVE-2026-51992
https://clickhouse.com/docs/sql-reference/dictionaries#postgresql