Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-01-20
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation and Full Compromise
Action: Patch when available
AI Analysis

Impact

A flaw in the Core component of Oracle VM VirtualBox allows an attacker with local high privileges to take complete control of the VirtualBox instance, thereby compromising confidentiality, integrity, and availability of the virtualized environment; the defect also enables a scope change that could undermine additional Oracle virtualization products.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox product is affected, specifically versions 7.1.14 and 7.2.4, with the vulnerability present in both releases.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 Base Score of 8.2 (AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H), signifying a severe local attack. The EPSS score of less than 1% indicates that exploitation in the wild is currently expected to be very rare. However, because the attack requires local high privileges, insiders or compromised host accounts could still leverage the flaw to fully compromise the VirtualBox instance. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on April 18, 2026 at 18:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security advisories for a vendor patch and apply it promptly.
  • Restrict local high‑privilege accounts to the minimum necessary for operation to reduce the attack surface for this vulnerability.
  • Monitor VirtualBox processes and logs for anomalous activity that could indicate an attempted exploitation of this local privilege escalation.

Generated by OpenCVE AI on April 18, 2026 at 18:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox Leading to Full Compromise
Weaknesses CWE-269
CWE-732

Thu, 29 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are 7.1.14 and 7.2.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.1.14:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:7.2.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-02-26T14:44:36.618Z

Reserved: 2026-01-05T18:07:34.717Z

Link: CVE-2026-21988

cve-icon Vulnrichment

Updated: 2026-01-29T16:32:33.056Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T22:16:02.353

Modified: 2026-01-29T14:39:39.690

Link: CVE-2026-21988

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T19:00:08Z