CVE-2026-21939
BaseFortify
Publication date: 2026-01-20
Last updated on: 2026-01-29
Assigner: Oracle
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oracle | database_server | From 23.4 (inc) to 23.26 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the SQLcl component of Oracle Database Server versions 23.4.0 to 23.26.0. It is difficult to exploit and requires an unauthenticated attacker to have logon access to the infrastructure where SQLcl runs. Additionally, successful exploitation requires human interaction from someone other than the attacker. If exploited, the attacker can take over SQLcl.
How can this vulnerability impact me? :
If successfully exploited, this vulnerability can lead to a complete takeover of SQLcl, impacting confidentiality, integrity, and availability of the system. This means sensitive data could be exposed or altered, and system operations could be disrupted.