Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle VM VirtualBox 7.2.12 product contains a flaw in its Core component that permits an actor with high‑privilege local access to read data that is otherwise protected. The weakness maps to information‑disclosure (CWE‑200) and is limited to confidentiality; there is no privilege escalation or disruption of host or guest systems. The description states the desire for high‑privilege logon, so the likely attack vector is local and requires elevated rights, as inferred from the advisory wording.

Affected Systems

Only Oracle Corporation’s VirtualBox version 7.2.12 is explicitly listed as affected. The CPE confirms this version, and no other vendors or product variations are known. The advisory mentions that other products may be impacted, but no specific details are provided.

Risk and Exploitability

The overall risk is low, with a CVSS base score of 3.2 and an EPSS probability of less than 1%. It is not included in the CISA KEV catalog. Because the vulnerability relies on local high‑privileged logon, remote exploitation is not possible. A successful exploit would grant unauthorized read access to a subset of data handled by VirtualBox, with potential indirect impact if scope expands, but no integrity or availability damage is expected.

Generated by OpenCVE AI on August 4, 2026 at 05:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any Oracle‑released update that mitigates the vulnerability in VirtualBox 7.2.12.
  • Restrict local administrative access on hosts running VirtualBox to minimize the number of high‑privilege users.
  • Monitor VirtualBox‑related system logs and host activity for anomalous read operations that may indicate exploitation.
  • If no patch is available, isolate affected hosts or block local connections from untrusted users until a fix is issued.

Generated by OpenCVE AI on August 4, 2026 at 05:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Local Privileged Access in Oracle VM VirtualBox 7.2.12

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Limited Confidentiality Impact via Local Privileged Attack in Oracle VM VirtualBox 7.2.12
Weaknesses CWE-284

Fri, 24 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Limited Confidentiality Impact via Local Privileged Attack in Oracle VM VirtualBox 7.2.12
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 3.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:39:07.145Z

Reserved: 2026-05-18T15:55:10.318Z

Link: CVE-2026-47043

cve-icon Vulnrichment

Updated: 2026-07-23T15:38:02.233Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:09.893

Modified: 2026-07-27T20:12:22.540

Link: CVE-2026-47043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor