SQL Injection Vulnerability in Oracle Database SQLcl Component
CVE-2026-21939
7HIGH
What is CVE-2026-21939?
A concerning SQL Injection vulnerability has been identified in the SQLcl component of Oracle Database Server that affects specific versions of the software. An unauthenticated attacker with access to the infrastructure where SQLcl operates could potentially exploit this vulnerability. However, successful exploitation requires some form of human interaction from another individual, which complicates the attack vector. If leveraged, this vulnerability could lead to unauthorized control over SQLcl, compromising the integrity, confidentiality, and availability of the databases it interfaces with.
Affected Version(s)
Oracle Database Server 23.4.0 <= 23.26.0