Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle VM VirtualBox 7.2.12 release contains a flaw in its Core component that permits a low‑privileged user who has logged onto the host system to trigger a crash or hang of the VirtualBox application. The vulnerability does not provide a path to code execution or privilege escalation; instead, successful exploitation results in a loss of availability for anyone relying on the VM host. The CVSS score of 5.5 reflects the significant impact on availability while indicating that confidentiality and integrity are unaffected.

Affected Systems

The affected product is Oracle Corporation’s Oracle VM VirtualBox version 7.2.12. No other major or minor releases of VirtualBox have been identified as impacted by this vulnerability. Administrators should verify that any deployed VirtualBox hosts are running this exact version and consider upgrading if possible.

Risk and Exploitability

The EPSS score of less than 1% suggests a low likelihood that attackers are attempting to exploit this issue in the wild. The vulnerability is not listed in the CISA KEV catalog, reinforcing its limited exploitation profile. Nevertheless, the availability impact can disrupt business operations if VirtualBox hosts are critical. The attack vector is inferred to be local: an attacker who can log onto the host system and execute code can push the vulnerable component through a trigger that causes a crash or hang. Patching the vulnerability removes the trigger and eliminates the risk of disruption.

Generated by OpenCVE AI on August 4, 2026 at 04:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for VirtualBox 7.2.12 or upgrade to a later version that contains the fix
  • Restrict local host access to users with the minimal required privileges so that an untrusted user cannot trigger the crash
  • Enable and monitor system logs for repeated crashes or hang events and apply additional protective measures if crashes are detected

Generated by OpenCVE AI on August 4, 2026 at 04:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Low-Privilege VirtualBox Crash Denying Availability

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title VirtualBox 7.2.12 Local Crash Vulnerability Leading to Denial of Service
Weaknesses CWE-400

Fri, 24 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title VirtualBox 7.2.12 Local Crash Vulnerability Leading to Denial of Service
Weaknesses CWE-400

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:06:15.364Z

Reserved: 2026-05-18T15:55:10.319Z

Link: CVE-2026-47062

cve-icon Vulnrichment

Updated: 2026-07-23T16:13:38.323Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:12.077

Modified: 2026-07-27T20:10:38.610

Link: CVE-2026-47062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses