Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-04-21
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

Vulnerability exists in the Core component of Oracle VM VirtualBox 7.2.6. A high‑privileged attacker who has logged on to the host system can exploit local privilege escalation to compromise the VirtualBox process, giving the attacker full control of the virtualization environment. The flaw can lead to significant confidentiality, integrity and availability impacts, and the description notes that attacks may also affect other products due to a scope change.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox 7.2.6 is the only version explicitly identified as affected.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a high level of severity. With no EPSS score provided, the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local; the attacker must have privileged access to the host machine. If successfully exploited, the attacker can take over VirtualBox, potentially pivoting to other services or systems that rely on converged virtualization. Given the scope change, the risk extends beyond the VirtualBox instance itself.

Generated by OpenCVE AI on April 22, 2026 at 04:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a fixed version of Oracle VM VirtualBox as recommended by Oracle’s security bulletin
  • Restrict local access to the VirtualBox host to trusted administrators and enforce least privilege
  • Segregate the VirtualBox network interfaces from critical infrastructure and monitor for anomalous activity

Generated by OpenCVE AI on April 22, 2026 at 04:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 05:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Leading to VirtualBox Takeover via Local Exploit
Weaknesses CWE-284
CWE-862

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.6:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-04-21T20:35:54.093Z

Reserved: 2026-04-01T20:03:40.834Z

Link: CVE-2026-35251

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-21T21:16:41.420

Modified: 2026-04-21T21:16:41.420

Link: CVE-2026-35251

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T04:45:09Z

Weaknesses