Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-01-20
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation leading to compromise of Oracle VM VirtualBox
Action: Immediate Patch
AI Analysis

Impact

A flaw in Oracle VM VirtualBox’s Core component allows a local attacker who already holds a high‑privileged account on the host to elevate privileges within the VirtualBox process and fully compromise it. This improper privilege management weakness (CWE‑269) can lead to loss of confidentiality, integrity and availability for VirtualBox and any dependent services. The vulnerability’s CVSS v3.1 base score is 7.5, reflecting significant impact when exploited. The description notes that attacks may affect additional products, indicating a potential scope change beyond the VirtualBox instance itself.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox versions 7.1.14 and 7.2.4 are affected. Systems running either release are vulnerable until a patched version is deployed.

Risk and Exploitability

The CVSS score of 7.5 and the EPSS of less than 1% indicate a moderate severity but a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and a high‑privileged user on the host; once achieved, an attacker can take over the VirtualBox instance, potentially impacting other products that rely on it. Attackers would need to log on to the host system running VirtualBox, and no external triggers are defined.

Generated by OpenCVE AI on April 18, 2026 at 15:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle VM VirtualBox to the latest patched version as announced in Oracle’s CPU Jan 2026 security alert
  • Restrict local access to the VirtualBox binaries and configuration files, granting only the minimum privileges necessary for normal operation
  • Disable or isolate VirtualBox services on production hosts that cannot be patched immediately, and monitor system logs for suspicious activity

Generated by OpenCVE AI on April 18, 2026 at 15:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox Due to Improper Privilege Management

Wed, 21 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.1.14:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:7.2.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-02-26T14:44:39.359Z

Reserved: 2026-01-05T18:07:34.713Z

Link: CVE-2026-21957

cve-icon Vulnrichment

Updated: 2026-01-21T15:55:56.891Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T22:15:58.613

Modified: 2026-01-29T16:01:46.750

Link: CVE-2026-21957

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T15:45:04Z

Weaknesses