Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Core component of Oracle VM VirtualBox version 7.2.14. An unauthenticated attacker who can reach the VirtualBox service over Remote Desktop Protocol can trigger a hang or complete crash, causing a repeatable denial of service. The CVSS 3.1 base score of 7.5 reflects a high availability impact while confidentiality and integrity remain unaffected. This weakness is identified as CWE-284.

Affected Systems

The affected product is Oracle VM VirtualBox from Oracle Corporation, specifically version 7.2.14. Users running this version on any operating system that exposes the RDP interface are at risk.

Risk and Exploitability

The attack vector is network-based via RDP, requiring no authentication. The vulnerability is described as easily exploitable. Without a patch the risk is high; the CVSS score is 7.5 and EPSS is < 1%, and the flaw is not listed in CISA KEV. Because the flaw allows complete denial of service, it can disrupt virtualization workloads and potentially affect service availability in environments that rely on VirtualBox.

Generated by OpenCVE AI on August 20, 2026 at 18:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle VM VirtualBox to a patched version that addresses the 7.2.14 vulnerability (check Oracle's security advisories).
  • If an immediate upgrade is not possible, block Remote Desktop access to VirtualBox from untrusted networks by configuring firewall rules or restricting the 3389 port.
  • Disable the RDP service if it is not required for VirtualBox operation, thereby removing the attack surface.

Generated by OpenCVE AI on August 20, 2026 at 18:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via RDP in Oracle VM VirtualBox 7.2.14

Thu, 20 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via RDP in Oracle VM VirtualBox 7.2.14

Wed, 19 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via RDP in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-20

Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via RDP in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-20

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:01:05.803Z

Reserved: 2026-08-04T22:06:34.618Z

Link: CVE-2026-71113

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:11.870

Modified: 2026-08-26T17:56:06.473

Link: CVE-2026-71113

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:30:04Z

Weaknesses