Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local vulnerability exists in Oracle VM VirtualBox version 7.2.12 that allows an unauthenticated attacker with logon access to the host system to compromise the Core component. Based on the description, it is inferred that the weakness involves a race condition or improper permission handling, leading to integrity and availability impacts. Successful exploitation can cause repeated crashes of VirtualBox (complete denial of service) and provide unauthorized update, insert, or delete access to data managed by VirtualBox.

Affected Systems

The affected product is Oracle VM VirtualBox 7.2.12 from Oracle Corporation. No other versions or variants are listed as impacted.

Risk and Exploitability

The risk remains moderate, reflected by a CVSS score of 6.1. The EPSS score of < 1 % indicates a low predicted exploitation probability. Exploitation requires the attacker to be logged into the host and leverages a separate local user to provide the necessary interaction, limiting the attack surface to local environments. The vulnerability is not listed in the CISA KEV catalog, further reducing the likelihood of widespread exploitation at present.

Generated by OpenCVE AI on August 2, 2026 at 23:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether Oracle has released an update for VirtualBox 7.2.12 and apply any available patches.
  • If a patch is not available, enforce strict user-level restrictions on the host so that only trusted accounts can run VirtualBox.
  • Monitor VirtualBox logs and host system activity for abnormal hangs or crashes, and investigate suspicious events promptly.

Generated by OpenCVE AI on August 2, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Race Condition Causing DOS and Unauthorized Data Modification in Oracle VM VirtualBox 7.2.12

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Vulnerability in Oracle VM VirtualBox 7.2.12 Allowing Denial of Service and Data Modification
Weaknesses CWE-732
CWE-862

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Vulnerability in Oracle VM VirtualBox 7.2.12 Allowing Denial of Service and Data Modification
Weaknesses CWE-732
CWE-862

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-362
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:13:47.118Z

Reserved: 2026-07-08T15:51:40.515Z

Link: CVE-2026-60161

cve-icon Vulnrichment

Updated: 2026-07-23T15:13:36.177Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T23:45:03Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')