Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Shared Folders). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-06-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the Shared Folders component of Oracle VM VirtualBox allows an attacker who has local logon to the host system to create, delete, or modify sensitive data stored in the shared folders. The flaw can be triggered using low‑privileged credentials, and the resulting impact is high confidentiality and integrity loss, as the modification or removal of critical data is possible. The CVE indicates no impact on availability, but the ability to tamper with data can compromise the integrity of virtual machines and their contents.

Affected Systems

This issue affects Oracle Corporation’s Oracle VM VirtualBox version 7.2.8. Only this specific version was listed in the advisory; other versions are not known to be vulnerable. The vulnerability resides in the virtual machine software responsible for handling shared folders between the host and guest operating systems.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate to high severity with a local attack vector, high attack complexity, low privileges required, and no need for user interaction. The EPSS score of less than 1% suggests that exploitation is unlikely in the wild, and the vulnerability is not catalogued in the CISA KEV list. However, because the defect allows an attacker with host access to compromise data on the virtual machine, the risk remains significant in environments where shared folders are enabled and local users have low privilege levels.

Generated by OpenCVE AI on June 17, 2026 at 20:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Oracle VM VirtualBox release (or apply any Oracle patch) that addresses the Shared Folders access control issue.
  • If an immediate update is not possible, disable the Shared Folders feature or restrict its usage to trusted users and remove shared folder configurations from untrusted guests.
  • Enforce strict local user privilege boundaries on the host machine and regularly audit which users can log in, ensuring only privileged accounts have access to the VirtualBox installation.

Generated by OpenCVE AI on June 17, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Shared Folders). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.8:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T14:09:56.148Z

Reserved: 2026-04-01T20:03:40.835Z

Link: CVE-2026-35275

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-16T22:00:12Z

Weaknesses

No weakness.