Description
Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where SQLcl executes to compromise SQLcl. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of SQLcl. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-01-20
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Application Takeover
Action: Patch Now
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Title Local SQLcl Tool Takeover Vulnerability in Oracle Database Server
Weaknesses CWE-285
CWE-730

Thu, 29 Jan 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle database Server

Wed, 21 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where SQLcl executes to compromise SQLcl. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of SQLcl. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle database - Sqlcl
CPEs cpe:2.3:a:oracle:database_-_sqlcl:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Sqlcl
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Database - Sqlcl Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-02-26T14:44:40.401Z

Reserved: 2026-01-05T18:07:34.711Z

Link: CVE-2026-21939

cve-icon Vulnrichment

Updated: 2026-01-21T20:59:27.734Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T22:15:56.663

Modified: 2026-01-29T20:34:46.243

Link: CVE-2026-21939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T19:15:10Z