CVEFinder.io

CVE-2026-21939

âš ī¸ high
🔍 Scan for this CVE
Summary

Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where SQLcl executes to compromise SQLcl. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of SQLcl. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts)

Description

Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where SQLcl executes to compromise SQLcl. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of SQLcl. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).

CVSS Score
7.0
High
EPSS Score
0.0
Exploit Probability
Published Date
2026-01-20
First Seen: 2026-01-28
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 51.7% of all 338,292 vulnerabilities in our database.

#163,550
Above average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Jan 21, 2026
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Total
Complete system compromise possible
SSVC data provided by CISA
Last Modified 2026-01-29
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

đŸ“Ļ Affected Products 1

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-46833 ⛔ critical 9.0 0.3 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2... 2026-05-28
CVE-2026-46834 âš ī¸ high 7.5 0.3 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2... 2026-05-28
CVE-2026-46835 âš ī¸ high 7.5 0.3 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2... 2026-05-28
CVE-2026-34312 â„šī¸ low 2.4 0.0 Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Ea... 2026-04-21
CVE-2025-53047 đŸ”ļ medium 5.8 0.0 Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are... 2025-10-21
CVE-2025-53051 â„šī¸ low 2.7 0.0 Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected a... 2025-10-21
These CVEs affect the same products