Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-01-20
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privileged Access Escalation
Action: Patch
AI Analysis

Impact

The vulnerability affects the core component of Oracle VM VirtualBox and allows a high‑privileged local attacker who already has logon access to the infrastructure to compromise the VirtualBox process. Successful exploitation leads to full takeover of the VirtualBox installation, affecting confidentiality, integrity, and availability of the virtualized environment. The weakness is a privilege‑management flaw that can grant attacker the same or higher privileges than the compromised VirtualBox process.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox versions 7.1.14 and 7.2.4 are impacted. The vulnerability is identified in the core component and may influence the operation or security of other Oracle Virtualization products that rely on VirtualBox.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 reflects a moderate‑to‑high severity, with local access (AV:L), high effort (AC:H), and high privileges (PR:H) required for exploitation. The EPSS score of less than 1 percent indicates that exploitation is relatively unlikely at the time of analysis. Because the threat requires local high‑privileged access, the risk for an unprivileged attacker is low, but inside organizations with local administrative users the possible impact is significant and can compromise additional products via the VirtualBox scope change.

Generated by OpenCVE AI on April 18, 2026 at 04:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle VM VirtualBox to a version that contains the security fix for this privilege‑escalation flaw.
  • Limit local user accounts to the minimum required privileges and apply least‑privilege principles to reduce the attack surface.
  • Monitor host system logs for anomalous activity that may indicate exploitation attempts or unauthorized changes to VirtualBox processes.

Generated by OpenCVE AI on April 18, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 04:45:00 +0000

Type Values Removed Values Added
Title Privileged Access Escalation in Oracle VM VirtualBox 7.1.14/7.2.4

Wed, 21 Jan 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.1.14:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:7.2.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-02-26T14:44:37.572Z

Reserved: 2026-01-05T18:07:34.716Z

Link: CVE-2026-21983

cve-icon Vulnrichment

Updated: 2026-01-21T14:25:33.424Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T22:16:01.763

Modified: 2026-01-29T14:40:25.600

Link: CVE-2026-21983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T04:30:35Z

Weaknesses