SQL Injection Vulnerability in Oracle Database SQLcl Component
CVE-2026-21939

7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
20 January 2026

What is CVE-2026-21939?

A concerning SQL Injection vulnerability has been identified in the SQLcl component of Oracle Database Server that affects specific versions of the software. An unauthenticated attacker with access to the infrastructure where SQLcl operates could potentially exploit this vulnerability. However, successful exploitation requires some form of human interaction from another individual, which complicates the attack vector. If leveraged, this vulnerability could lead to unauthorized control over SQLcl, compromising the integrity, confidentiality, and availability of the databases it interfaces with.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Oracle Database Server 23.4.0 <= 23.26.0

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.