Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L).
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is in the core component of Oracle VM VirtualBox 7.2.12 and is described as an authorization weakness that allows a local user with high privilege to bypass access controls. A successful exploitation grants the attacker read or write access to all VirtualBox‑managed data and the capability to cause a partial denial of service on the host. The weakness is mapped to privilege escalation (CWE‑269).

Affected Systems

Oracle VM VirtualBox version 7.2.12 installed on host machines within the infrastructure. No other product versions are listed as affected in the advisory.

Risk and Exploitability

The CVSS v3.1 base score of 6.1 reflects high confidentiality impact and low availability impact, with the attack vector classified as local and requiring high privileges. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog, suggesting no publicly known exploits. Based on the description, the likely attack vector is a local privilege exploitation in an environment where a trusted user has logged into the host system running VirtualBox.

Generated by OpenCVE AI on August 4, 2026 at 17:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle VM VirtualBox update that addresses CVE-2026-60162 to correct the authorization flaw
  • Limit host system access so that only trusted administrators can run VirtualBox, removing or restricting accounts that could execute VirtualBox with high privileges
  • Enable audit logging for VirtualBox operations and monitor for anomalous activity that could indicate exploitation attempts

Generated by OpenCVE AI on August 4, 2026 at 17:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Authorization Weakness in Oracle VM VirtualBox 7.2.12 Allows Local Privileged Access and Partial Denial of Service

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Authorization Weakness in Oracle VM VirtualBox 7.2.12 Allows Local Privileged Access and Partial Denial of Service

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title High‑Privilege Local Access Vulnerability in Oracle VM VirtualBox
Weaknesses CWE-276
CWE-285

Fri, 24 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title High‑Privilege Local Access Vulnerability in Oracle VM VirtualBox
Weaknesses CWE-276
CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.12:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:26:41.491Z

Reserved: 2026-07-08T15:51:40.516Z

Link: CVE-2026-60162

cve-icon Vulnrichment

Updated: 2026-07-23T15:12:38.621Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:16.890

Modified: 2026-07-30T20:15:52.160

Link: CVE-2026-60162

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management