
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52969 is a rejected/withdrawn CVE originally describing an access control issue in ClickHouse 25.7.1.557, where low-privileged users could execute shell commands by querying existing Executable() tables created by higher-privileged users. The CVE Numbering Authority (MITRE) has since rejected this CVE ID. The EUVD entry (EUVD-2025-18907) assigned it a CVSS v3.1 base score of 2.8 (Low), though Feedly's estimate categorized it as High prior to rejection (Red Hat Advisory, EUVD).
The originally reported issue involved CWE-420 (Unprotected Alternate Channel): low-privileged users could invoke Executable() table engine entries already present in the system without requiring the CREATE TABLE privilege themselves. If an attacker could also influence the contents of the script referenced by the Executable() engine (e.g., via writable file paths), they could execute controlled commands in the context of the ClickHouse server process. The vendor's stated position is that this behavior — low-privileged users querying existing Executable() tables — is expected and by design, which contributed to the CVE's rejection (EUVD, Security Research).
As originally described, successful exploitation could lead to privilege escalation and unauthorized code execution in the context of the ClickHouse server, with limited integrity impact (CVSS integrity: Low, confidentiality: None). However, given the CVE has been rejected by its CNA and the vendor considers the behavior expected, the practical security impact is disputed and not formally recognized as a vulnerability (EUVD).
The EPSS score for this CVE is approximately 0.012% (0.000120), indicating very low probability of exploitation in the wild. There is no evidence of active exploitation, no known exploit kits, and no CISA KEV catalog listing. The CVE has been formally rejected, further reducing its operational relevance (Red Hat Advisory, EUVD).
Because this CVE has been rejected by its CNA and the vendor (ClickHouse) considers the described behavior to be expected functionality, no official patch has been issued. Organizations concerned about low-privileged users accessing Executable() tables should review and restrict access controls on existing Executable() table objects, audit writable paths accessible to the ClickHouse server process, and apply the principle of least privilege to database user roles (EUVD).
The vendor's (ClickHouse's) explicit position is that execution of queries against existing Executable() tables by low-privileged users is intended behavior, which led to the CVE being rejected. Red Hat tracked the CVE but it remains in a rejected state with no further action. No significant broader community or media discussion has been identified beyond initial aggregator coverage (Red Hat Advisory, EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."