Vulnerability in ClickHouse Plugin for Grafana by Grafana Labs
CVE-2026-19854

6.1MEDIUM

Key Information:

Vendor

Grafana

Vendor
CVE Published:
27 August 2026

What is CVE-2026-19854?

A security flaw in the ClickHouse plugin for Grafana arises when it utilizes the Native protocol combined with a PDC or secure SOCKS configuration. The plugin requests a TLS connection; however, the underlying connection library does not honor this request and transmits data unencrypted. Consequently, sensitive information such as usernames, passwords, queries, and results can be intercepted during transmission. Furthermore, the server's certificate is not validated, and any configured client certificate fails to transmit, significantly compromising data integrity and confidentiality.

Affected Version(s)

Clickhouse Datasource 3.1.0 <= 4.20.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.