Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).
Published: 2026-07-21
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle VM VirtualBox 7.2.8 permits an attacker who already holds a local high-privileged account to compromise the virtual machine manager. Successful exploitation requires a second person to interact with the system, but once the conditions are met the attacker can create, delete, or modify critical data and can cause repeated crashes that result in a complete denial of service. Confidentiality is not directly impacted, however integrity and availability are significantly affected. The weakness can be classified as CWE-284 (Improper Access Control).

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox version 7.2.8 is the only documented affected product. The CPE string confirms this version, and no other revisions are listed as vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 7.4 indicates a high impact on integrity and availability, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA KEV, meaning no publicly known active exploitation. Attackers would need local access and elevated privileges, and the need for user interaction from a different individual may further limit potential risk, though the scope-change attribute indicates that other Oracle products could be impacted once the exploit is successful.

Generated by OpenCVE AI on August 2, 2026 at 23:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle VM VirtualBox to the latest available version that includes the vendor’s security fix.
  • Limit local high-privileged accounts on the host system to trusted administrators only and enforce the principle of least privilege.
  • Enable logging and monitor for unauthorized file changes or repeated crashes on the virtualization host.
  • Isolate the virtualization host from untrusted networks and restrict unnecessary privileged services.

Generated by OpenCVE AI on August 2, 2026 at 23:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Data Tampering and Denial of Service in Oracle VM VirtualBox 7.2.8

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Data Tampering and Denial of Service in Oracle VM VirtualBox 7.2.8

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.8:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:29:41.622Z

Reserved: 2026-05-18T15:55:10.319Z

Link: CVE-2026-47050

cve-icon Vulnrichment

Updated: 2026-07-23T15:29:35.080Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:00:04Z

Weaknesses