CVE-2026-19854 MEDIUM

CVE-2026-19854: CVE-2026-19854 CVE Record

Vendor Grafana
Product Clickhouse Datasource
Weakness CWE-319 · Cleartext transmission
Published August 27, 2026
Last update August 27, 2026

CVSS base score

6.1/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N

What the vulnerability does

01Description

When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a configured client certificate is not sent.

Key dates

02Disclosure timeline

August 27, 2026 CVE published
August 27, 2026 Record updated