Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L).
Published: 2026-07-21
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle VM VirtualBox 7.2.12 stems from an Access Control weakness (CWE‑284). It permits a low‑privileged user with local logon access to create, delete, or modify data within the VirtualBox environment, and to induce a partial denial of service. The impact is a high‑risk integrity breach for VirtualBox‑managed data and a medium‑risk availability disruption.

Affected Systems

Oracle VirtualBox 7.2.12 on any host system is affected. The flaw may also influence other products that are used in conjunction with VirtualBox because the vulnerability’s scope is marked as "change," indicating that exploitation can affect additional components.

Risk and Exploitability

The CVSS 3.1 base score of 6.4 indicates moderate severity with high integrity impact and low availability impact. The EPSS score is less than 1%, showing a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires local access from a user with low privileges on the host system, making it less attractive to threat actors but still relevant for in‑house adversaries or compromised accounts. The high difficulty of exploitation (AC:H, PR:L) limits the likelihood of successful attacks, though the potential damage remains significant.

Generated by OpenCVE AI on August 4, 2026 at 17:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle VM VirtualBox to the latest patched release, such as 7.2.13 or newer
  • Enforce strict local‑user privileges on the host, removing any unnecessary accounts or reducing their permissions
  • Continuously monitor VirtualBox configuration files and disk images for unauthorized changes or signs of partial downtime

Generated by OpenCVE AI on August 4, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Oracle VM VirtualBox 7.2.12 Access Control Flaw Enables Local Data Tampering and Partial DoS

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Vulnerability in Oracle VM VirtualBox Enabling Unauthorized Data Access and Partial Denial of Service

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Vulnerability in Oracle VM VirtualBox Enabling Unauthorized Data Access and Partial Denial of Service

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:15:36.323Z

Reserved: 2026-07-08T15:51:40.515Z

Link: CVE-2026-60158

cve-icon Vulnrichment

Updated: 2026-07-23T15:15:30.885Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:16.433

Modified: 2026-07-28T01:36:13.947

Link: CVE-2026-60158

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses