Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerable component in the core of Oracle VM VirtualBox permits an attacker who has local access to the host to compromise the VirtualBox process, leading to a full takeover of the virtualization environment. The flaw causes loss of confidentiality, integrity, and availability of the VirtualBox service, essentially allowing the attacker to operate with the same privileges as VirtualBox itself.

Affected Systems

Oracle Corporation’s VirtualBox 7.2.12 for Windows hosts is affected; no other versions or operating systems are listed as vulnerable.

Risk and Exploitability

The vulnerability has a CVSS v3.1 base score of 7.8, indicating high severity, yet the EPSS score is below 1 % and it is not currently listed in CISA’s KEV catalog. The likely attack vector requires an attacker to have a local account or otherwise log on to the infrastructure where VirtualBox is running. Successful exploitation enables the attacker to take over the VirtualBox service, potentially leading to the compromise of virtual machines and other host functions.

Generated by OpenCVE AI on August 5, 2026 at 02:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle VM VirtualBox to the latest version that contains the fix (≥ 7.2.13).
  • Restrict local account privileges to mitigate improper privilege management (CWE-269); ensure only necessary users can launch or administer VirtualBox on Windows hosts.
  • Enforce host‑level hardening: apply least‑privilege policies, enable auditing, and keep the host OS patched to mitigate related security gaps.

Generated by OpenCVE AI on August 5, 2026 at 02:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Host Compromise via Oracle VM VirtualBox Core Vulnerability
Weaknesses CWE-284

Fri, 24 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Host Compromise via Oracle VM VirtualBox Core Vulnerability
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:54.587Z

Reserved: 2026-05-18T15:55:10.319Z

Link: CVE-2026-47054

cve-icon Vulnrichment

Updated: 2026-07-23T15:26:49.837Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:11.133

Modified: 2026-07-28T05:17:06.350

Link: CVE-2026-47054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:15:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management