Description
Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where SQLcl executes to compromise SQLcl. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of SQLcl. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-01-20
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Application Takeover
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the SQLcl component of Oracle Database Server and permits an unauthenticated user who has already logged into the host system to compromise the SQLcl process. The flaw requires the cooperation of a separate person to trigger exploitation, indicating that user interaction is needed. Once an attacker achieves control of SQLcl, the tool can be used to read, modify, or delete data accessed through the database, resulting in confidentiality, integrity, and availability impacts. The official description does not explicitly state the data‑manipulation capabilities; those consequences are inferred from the fact that SQLcl is a database client that can execute arbitrary SQL statements.

Affected Systems

Oracle Database Server versions 23.4.0 through 23.26.0 are affected; the issue applies to all builds of SQLcl distributed as part of these releases.

Risk and Exploitability

The CVSS 3.1 base score of 7.0 signals serious risk, yet the attack vector is limited to local access (AV:L) and requires user interaction (UI:R). No authentication is required from the attacker (PR:N), but the exploitation effort is high (AC:H). The EPSS score of less than 1% and absence from CISA’s KEV catalog suggest a low likelihood of widespread exploitation, yet the potential for a localized takeover of a database interface tool warrants timely action. If an attacker were to succeed, the resulting compromise would allow alteration of data and potentially disrupt database availability.

Generated by OpenCVE AI on April 18, 2026 at 19:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest Database Server release beyond 23.26.0 that contains the SQLcl fix.
  • Restrict or remove the SQLcl utility from systems where it is not required for operations.
  • Limit user interaction required for SQLcl commands by enforcing least‑privilege policies and monitoring usage.

Generated by OpenCVE AI on April 18, 2026 at 19:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Title Local SQLcl Tool Takeover Vulnerability in Oracle Database Server
Weaknesses CWE-285
CWE-730

Thu, 29 Jan 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*
Vendors & Products Oracle database Server

Wed, 21 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where SQLcl executes to compromise SQLcl. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of SQLcl. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle database - Sqlcl
CPEs cpe:2.3:a:oracle:database_-_sqlcl:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Sqlcl
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Database - Sqlcl Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-02-26T14:44:40.401Z

Reserved: 2026-01-05T18:07:34.711Z

Link: CVE-2026-21939

cve-icon Vulnrichment

Updated: 2026-01-21T20:59:27.734Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T22:15:56.663

Modified: 2026-01-29T20:34:46.243

Link: CVE-2026-21939

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T19:15:10Z