Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).
Published: 2026-07-21
Score: 3.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Core component of Oracle VM VirtualBox 7.2.12 and permits an attacker who is a high‑privileged user with local logon to the host machine to read a subset of data that should be restricted, representing an Information Exposure weakness (CWE‑200). The weakness results in a confidentiality impact, with no influence on integrity or availability. The CVSS vector indicates a local attack that requires high privileges and results in read‑only exposure, leading to a Base Score of 3.2.

Affected Systems

Oracle Corporation’s virtual machine platform, Oracle VM VirtualBox, specifically version 7.2.12 is affected. No other precise versions are listed, but the text suggests the issue may also influence other products within the Oracle Virtualization suite due to a scope change.

Risk and Exploitability

The CVSS score of 3.2 coupled with an EPSS score of less than 1% signifies a low overall exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local access to a machine running the affected VirtualBox instance and requires high‑privilege credentials, limiting the attacker’s reach to machine‑level controls.

Generated by OpenCVE AI on August 4, 2026 at 04:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict local high‑privileged accounts on hosts that run VirtualBox 7.2.12 to only those necessary for virtualization management.
  • Segment the virtual‑box host network from critical infrastructure to limit lateral movement and data exposure.
  • Monitor Oracle’s security advisories and upgrade to any patched version of VirtualBox as soon as it becomes available.

Generated by OpenCVE AI on August 4, 2026 at 04:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local High-Privilege Information Exposure in Oracle VM VirtualBox 7.2.12

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via Local Privileged Attack in Oracle VM VirtualBox 7.2.12

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Read Access via Local Privileged Attack in Oracle VM VirtualBox 7.2.12

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 3.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:14:23.405Z

Reserved: 2026-07-08T15:51:40.515Z

Link: CVE-2026-60160

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:15.673Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor