Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle VM VirtualBox version 7.2.14 contains a flaw in its core component that can be exploited by a user who already has a logon to the host running VirtualBox. The vulnerability requires the attacker to be a high privileged local user and is difficult to exploit, but a successful attack would give the attacker comprehensive control over the VirtualBox instance, allowing full compromise of the product’s confidentiality, integrity and availability. The flaw also carries a scope change risk, potentially affecting other dependent products on the same host.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox, specifically the 7.2.14 release. No other products or versions are listed as affected.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 signals medium to high severity; its Local attack vector (AV:L) combined with the required high privilege (PR:H) means the attack can only be carried out in an environment where the attacker has already logged on. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not yet actively exploited. Nonetheless, because the flaw can change the scope of the attack and lead to complete takeover of VirtualBox, the potential impact is significant if the conditions are met.

Generated by OpenCVE AI on August 20, 2026 at 11:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch or upgrade to Oracle VM VirtualBox 7.2.15 or later.
  • Disable or restrict local access to VirtualBox for non‑administrator accounts, ensuring that only authorized users can launch or manage virtual machines.
  • Audit host system accounts to ensure no unnecessary high‑privileged accounts exist; remove or demote them, and monitor for suspicious local privilege escalations.

Generated by OpenCVE AI on August 20, 2026 at 11:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title High Privileged Local Attack Exploits Oracle VirtualBox for Full System Compromise
Weaknesses CWE-285

Wed, 19 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title High Privileged Local Attack Exploits Oracle VirtualBox for Full System Compromise
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T03:56:27.774Z

Reserved: 2026-08-04T22:06:34.618Z

Link: CVE-2026-71116

cve-icon Vulnrichment

Updated: 2026-08-19T15:02:27.605Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:12.223

Modified: 2026-08-26T17:56:30.980

Link: CVE-2026-71116

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:15:03Z

Weaknesses