ClickHouse has a permission bypass vulnerability where unprivileged users can read restricted data by disabling query validation in UPDATE mutations, which execute with full database privileges. The issue affects ClickHouse 26 and was rejected by the vendor's disclosure program.