Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.6 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L).
Published: 2026-07-21
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Core component of Oracle VM VirtualBox permits a local logged‑in user to compromise the VirtualBox process with low privileges. The vulnerable 7.2.12 version can be abused to create, delete, or modify critical data that VirtualBox manages and can lead to a partial denial of service. The weakness is an improper access control problem that undermines the integrity and availability of VirtualBox data, as reflected in the CVSS vector showing high impact on integrity and low impact on availability.

Affected Systems

The affected product is Oracle VirtualBox version 7.2.12 from Oracle Corporation. No other versions or products are listed as impacted in the available CNA data.

Risk and Exploitability

The CVSS Base Score of 5.6 classifies the issue as moderate severity, and the EPSS figure of less than 1 % indicates that the probability of exploitation is currently very low. The vulnerability is not included in the CISA KEV catalog, suggesting it has not yet been widely exploited. Exploitation requires a local attacker with access to the infrastructure where VirtualBox runs and necessitates human interaction from a user other than the attacker, implying that social engineering or an internal collaborator would be needed for successful attacks.

Generated by OpenCVE AI on August 4, 2026 at 05:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle VM VirtualBox update that addresses the 7.2.12 vulnerability.
  • Restrict local user accounts that can run VirtualBox to only those necessary and enforce least‑privilege policies.
  • Disable or closely monitor VirtualBox execution on untrusted or sensitive machines; consider removing it from servers that do not require the hypervisor.

Generated by OpenCVE AI on August 4, 2026 at 05:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Local Logon Compromise Allows Unauthorized Access to Oracle VirtualBox Data and Partial Denial of Service

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local Logon Compromise Allows Unauthorized Access to Oracle VirtualBox Data and Partial Denial of Service

Mon, 27 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Local Privileges Allow Data Tampering and Partial Denial of Service in Oracle VM VirtualBox 7.2.12
Weaknesses CWE-284

Fri, 24 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Local Privileges Allow Data Tampering and Partial Denial of Service in Oracle VM VirtualBox 7.2.12
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.6 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:27:33.121Z

Reserved: 2026-05-18T15:55:10.319Z

Link: CVE-2026-47053

cve-icon Vulnrichment

Updated: 2026-07-23T15:27:25.688Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:11.020

Modified: 2026-07-27T20:11:23.757

Link: CVE-2026-47053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses