SQL Injection Vulnerability in Oracle Database SQLcl Component
CVE-2026-21939
What is CVE-2026-21939?
A concerning SQL Injection vulnerability has been identified in the SQLcl component of Oracle Database Server that affects specific versions of the software. An unauthenticated attacker with access to the infrastructure where SQLcl operates could potentially exploit this vulnerability. However, successful exploitation requires some form of human interaction from another individual, which complicates the attack vector. If leveraged, this vulnerability could lead to unauthorized control over SQLcl, compromising the integrity, confidentiality, and availability of the databases it interfaces with.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Oracle Database Server 23.4.0 <= 23.26.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved