Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N).
Published: 2026-07-21
Score: 3.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Oracle VM VirtualBox 7.2.12 allows an attacker who already possesses high‑privilege access to the host machine to perform unauthorized updates, insertions, or deletions of data that the hypervisor can access. This activity results in a violation of data integrity, and because the vulnerability can cause a scope change, adjacent VirtualBox‑controlled components may also be affected.

Affected Systems

The affected product is Oracle VirtualBox version 7.2.12. No other versions or Oracle products are listed as impacted by this issue.

Risk and Exploitability

The CVSS score of 3.2 indicates a moderate integrity risk, and the EPSS score of less than 1% suggests that exploitation is unlikely but not impossible in environments where an attacker can log in locally with elevated privileges. The vulnerability is not listed in CISA KEV. Exploitation requires local presence and high privileges; the attacker can then modify VirtualBox data, potentially influencing the configuration or state of other components controlled by VirtualBox after a scope change.

Generated by OpenCVE AI on August 4, 2026 at 04:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle VM VirtualBox to a version where the vulnerability is fixed, such as 7.2.13 or later.
  • Restrict local privileged access to the host system and limit who can log in with administrative rights to run VirtualBox.
  • Enable audit logging on VirtualBox interfaces and regularly review logs for unauthorized data manipulation activities.

Generated by OpenCVE AI on August 4, 2026 at 04:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allows Integrity Compromise in Oracle VM VirtualBox 7.2.12

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allows Integrity Compromise in Oracle VM VirtualBox 7.2.12

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox Enabling Unauthorized Data Modification
Weaknesses CWE-640

Fri, 24 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox Enabling Unauthorized Data Modification
Weaknesses CWE-640

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 3.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:26:19.228Z

Reserved: 2026-05-18T15:55:10.319Z

Link: CVE-2026-47055

cve-icon Vulnrichment

Updated: 2026-07-23T15:26:13.024Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:11.253

Modified: 2026-07-27T20:11:03.580

Link: CVE-2026-47055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses