Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-52969
ClickHouse vulnerability analysis and mitigation

Overview

CVE-2025-52969 is a rejected/withdrawn CVE originally describing an access control issue in ClickHouse 25.7.1.557, where low-privileged users could execute shell commands by querying existing Executable() tables created by higher-privileged users. The CVE Numbering Authority (MITRE) has since rejected this CVE ID. The EUVD entry (EUVD-2025-18907) assigned it a CVSS v3.1 base score of 2.8 (Low), though Feedly's estimate categorized it as High prior to rejection (Red Hat Advisory, EUVD).

Technical details

The originally reported issue involved CWE-420 (Unprotected Alternate Channel): low-privileged users could invoke Executable() table engine entries already present in the system without requiring the CREATE TABLE privilege themselves. If an attacker could also influence the contents of the script referenced by the Executable() engine (e.g., via writable file paths), they could execute controlled commands in the context of the ClickHouse server process. The vendor's stated position is that this behavior — low-privileged users querying existing Executable() tables — is expected and by design, which contributed to the CVE's rejection (EUVD, Security Research).

Impact

As originally described, successful exploitation could lead to privilege escalation and unauthorized code execution in the context of the ClickHouse server, with limited integrity impact (CVSS integrity: Low, confidentiality: None). However, given the CVE has been rejected by its CNA and the vendor considers the behavior expected, the practical security impact is disputed and not formally recognized as a vulnerability (EUVD).

Exploitability

The EPSS score for this CVE is approximately 0.012% (0.000120), indicating very low probability of exploitation in the wild. There is no evidence of active exploitation, no known exploit kits, and no CISA KEV catalog listing. The CVE has been formally rejected, further reducing its operational relevance (Red Hat Advisory, EUVD).

Mitigation and workarounds

Because this CVE has been rejected by its CNA and the vendor (ClickHouse) considers the described behavior to be expected functionality, no official patch has been issued. Organizations concerned about low-privileged users accessing Executable() tables should review and restrict access controls on existing Executable() table objects, audit writable paths accessible to the ClickHouse server process, and apply the principle of least privilege to database user roles (EUVD).

Community reactions

The vendor's (ClickHouse's) explicit position is that execution of queries against existing Executable() tables by low-privileged users is intended behavior, which led to the CVE being rejected. Red Hat tracked the CVE but it remains in a rejected state with no further action. No significant broader community or media discussion has been identified beyond initial aggregator coverage (Red Hat Advisory, EUVD).

Additional resources


SourceThis report was generated using AI

Related ClickHouse vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2019-16536HIGH8.2
  • ClickHouse logoClickHouse
  • clickhouse
NoYesMay 21, 2025
CVE-2024-6873HIGH8.1
  • ClickHouse logoClickHouse
  • clickhouse
NoNoAug 01, 2024
CVE-2025-1385HIGH7.5
  • ClickHouse logoClickHouse
  • clickhouse
NoNoMar 20, 2025
CVE-2024-41436HIGH7.5
  • ClickHouse logoClickHouse
  • clickhouse
NoYesSep 03, 2024
CVE-2025-52969NONEN/A
  • ClickHouse logoClickHouse
  • clickhouse
NoNoJun 23, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management