Cleartext transmission of sensitive information in Clickhouse Datasource - CVE-2026-19854

 

Cleartext transmission of sensitive information in Clickhouse Datasource - CVE-2026-19854

Published: September 1, 2026


Vulnerability identifier: #VU146534
CSH Severity: Medium
CVSS v4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-19854
CWE-ID: CWE-319
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software uses insecure communication channel to transmit sensitive information when using Native protocol (the default) with PDC or secure SOCKS. A remote attacker on the local network can gain access to sensitive data.


Affected software

Clickhouse Datasource

How to mitigate CVE-2026-19854

Install updates from vendor's website.

Clickhouse Datasource - update to 4.21.1

External References

Related Security Bulletins