
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21939 is a local code execution vulnerability in the SQLcl component of Oracle Database Server, affecting versions 23.4.0 through 23.26.0. It was disclosed on January 20, 2026, as part of Oracle's Critical Patch Update (CPU) for January 2026. The vulnerability is difficult to exploit, requires local access to the infrastructure where SQLcl executes, and necessitates human interaction from a person other than the attacker. It carries a CVSS v3.1 base score of 7.0 (High) (Oracle CPU Jan 2026).
The vulnerability resides in the SQLcl component of Oracle Database Server and is classified as a local attack vector (CWE details not publicly specified by Oracle). An unauthenticated attacker with logon access to the infrastructure where SQLcl executes can exploit this flaw, but only when a legitimate user interacts with the environment in a way that triggers the vulnerability — a social engineering or user-interaction dependency. The high attack complexity reflects the difficulty in reliably meeting the required conditions. This vulnerability also affects client-only Oracle Database Server installations, meaning systems without the full database server installed are still at risk if SQLcl is present (Oracle CPU Jan 2026). The vulnerability was reported to Oracle by Akira Hachiya (Oracle CPU Jan 2026).
Successful exploitation results in a complete takeover of SQLcl, with high impacts to confidentiality, integrity, and availability. An attacker could execute arbitrary code and gain full control over SQLcl's processes and data, potentially accessing sensitive database credentials or query results handled by the tool. Because SQLcl is a command-line interface for Oracle Database, compromise could serve as a stepping stone for further lateral movement within database environments (Oracle CPU Jan 2026).
Oracle has released patches for this vulnerability as part of the January 2026 Critical Patch Update. Affected users running SQLcl versions 23.4.0 through 23.26.0 should apply the available security patch immediately. As interim measures, organizations should restrict local system access to trusted users only, implement security awareness training to reduce the risk of user interaction being exploited, and monitor SQLcl execution for anomalous behavior. Oracle strongly recommends applying Critical Patch Update patches without delay rather than relying on workarounds (Oracle CPU Jan 2026).
The vulnerability received standard coverage following Oracle's January 2026 CPU release, with automated security feeds and vulnerability tracking platforms (including Nessus plugin 296378) picking up the advisory. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-21939 has been identified beyond routine vulnerability aggregation (Oracle CPU Jan 2026).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."