Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Core component of Oracle VM VirtualBox 7.2.12 allows an attacker who has a high‑privileged logon to the host infrastructure to fully compromise the VirtualBox instance. The CVSS 3.1 score of 7.5 reflect significant effects on confidentiality, integrity and availability, and the exploit can lead to a complete takeover of the VirtualBox installation.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox product, specifically version 7.2.12, is affected. No other versions are listed as vulnerable.

Risk and Exploitability

An attacker must already have high privileged access on the host (AV:L, PR:H) and does not need a user interface (UI:N). The EPSS score is less than 1 %, indicating current exploitation probability is low, and the vulnerability is not included in the CISA KEV catalog. Based on the description, it is inferred that successful exploitation may impact additional products, indicating potential pivot to compromise other components within the same infrastructure. Nonetheless, the impact remains grave; if exploited, the attacker can achieve full control over the VirtualBox instance and potentially extend influence to other parts of the environment.

Generated by OpenCVE AI on August 5, 2026 at 02:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify that Oracle has released a patch for this vulnerability and apply it when available.
  • Implement stricter access controls to prevent unauthorized high‑privileged actions, addressing the CWE‑284 vulnerability type, and enforce the principle of least privilege for host users.
  • Monitor host activity for signs of root‑kit or virtualization‑related anomalies, and implement intrusion detection specifically targeting unauthorized virtualization changes.

Generated by OpenCVE AI on August 5, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title High‑Privileged Local Exploit Allows Full Compromise of Oracle VM VirtualBox 7.2.12

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title High‑Privileged Local Exploit Allows Full Compromise of Oracle VM VirtualBox 7.2.12

Tue, 28 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing VirtualBox Takeover in Oracle VM VirtualBox 7.2.12

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing VirtualBox Takeover in Oracle VM VirtualBox 7.2.12
Weaknesses CWE-284

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:56.832Z

Reserved: 2026-07-08T15:51:40.515Z

Link: CVE-2026-60159

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:47.540Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:15:03Z

Weaknesses