Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-01-20
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Boolean compromise of Oracle VM VirtualBox through local privilege escalation
Action: Immediate Patch
AI Analysis

Impact

Vulnerability in the Core component of Oracle VM VirtualBox allows a high-privileged local attacker to compromise the software. A single successful exploit can lead to full takeover with confidentiality, integrity, and availability impact for the virtualized environment. The CVSS vector indicates a local attack with low AC, high privilege and unchanged UI, but a changed scope that may affect additional products.

Affected Systems

Oracle works through its VirtualBox product line. Versions 7.1.14 and 7.2.4 are confirmed to be affected. Users running these releases are at risk until a patch or newer release is applied.

Risk and Exploitability

The CVSS base score of 8.2 classifies this flaw as high risk. EPSS is below 1% and it is not listed in the CISA KEV catalog, suggesting exploitation probability remains low at present. However, because the vulnerability requires local access with high privileges, any compromised host or insider attacker can immediately exercise this flaw, potentially allowing full control of the virtualization stack. The impact extends beyond Oracle VM VirtualBox due to the scope change, potentially affecting other products dependent on or integrated with the virtual environment.

Generated by OpenCVE AI on April 18, 2026 at 15:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle VM VirtualBox to a non-affected version (any release newer than 7.1.14 or 7.2.4).
  • If an immediate patch is not available, isolate the hosts running VirtualBox from untrusted networks and monitor for suspicious activity within the hypervisor.
  • Apply all other relevant host OS security updates to reduce the risk of local privilege exploits that could target VirtualBox.

Generated by OpenCVE AI on April 18, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 16:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox Core Component
Weaknesses CWE-250
CWE-269

Thu, 29 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.1.14:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:7.2.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-02-26T14:44:36.929Z

Reserved: 2026-01-05T18:07:34.717Z

Link: CVE-2026-21987

cve-icon Vulnrichment

Updated: 2026-01-29T16:32:50.881Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T22:16:02.237

Modified: 2026-01-29T14:39:49.067

Link: CVE-2026-21987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T15:45:04Z