Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the core component of Oracle VM VirtualBox 7.2.12 and allows an attacker with high‑privileged local access on the host to take full control of the VirtualBox application. The flaw can compromise confidentiality, integrity, and availability of the virtualized environment. Based on the description, a takeover of the VirtualBox process could potentially affect the host system, but this is an inference.

Affected Systems

Oracle VM VirtualBox version 7.2.12, the only affected version listed. The product is Oracle Corporation’s virtualization platform.

Risk and Exploitability

The CVSS v3.1 Base Score of 7.5 reflects the high severity of this local privilege escalation. The EPSS score is reported as <1%, indicating that attacks are anticipated to be rare. The alert is not listed in CISA’s KEV catalog, but the scope change vector (S:C) in the CVSS definition signals that successful exploitation could affect other products that depend on VirtualBox components. Successful exploitation requires an attacker to first log on locally with high privileges and then trigger the exploit to gain control of both the VirtualBox process and any dependent components; while a takeover of the VirtualBox process could potentially influence the host, this impact is inferred from the description.

Generated by OpenCVE AI on August 4, 2026 at 04:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle VM VirtualBox to the latest release that contains the fix for version 7.2.12.
  • Restrict local administrative access to the host and enforce strict least‑privilege policies; separate the VirtualBox process from other critical services.
  • Enable logging and monitoring on the VirtualBox host to detect anomalous behavior indicative of a takeover.
  • Implement proper authorization controls to prevent unauthorized local privileged operations within VirtualBox.

Generated by OpenCVE AI on August 4, 2026 at 04:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title High‑Privileged Local Vulnerability Allows Full Takeover of Oracle VM VirtualBox

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title High‑Privileged Local Vulnerability Allows Full Takeover of Oracle VM VirtualBox

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox 7.2.12 Allows Complete Takeover
Weaknesses CWE-862

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox 7.2.12 Allows Complete Takeover
Weaknesses CWE-284
CWE-862

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:56.086Z

Reserved: 2026-07-08T15:51:40.515Z

Link: CVE-2026-60155

cve-icon Vulnrichment

Updated: 2026-07-23T15:17:38.895Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses