Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the core component of Oracle VM VirtualBox version 7.2.14. It enables an attacker who already has a low‑privileged account on a host that runs VirtualBox to compromise the VirtualBox process, leading to full takeover. Successful exploitation results in loss of confidentiality, integrity, and availability of the VirtualBox installation. Because the vulnerability has a scope change, a compromised VirtualBox instance may also be used to affect other products running on the same infrastructure.

Affected Systems

Oracle VM VirtualBox 7.2.14, a product of Oracle Corporation. Only this specific major/minor version is affected.

Risk and Exploitability

The CVSS 3.1 base score of 7.8 indicates high severity, with high attack complexity and local access required. The EPSS score is reported as <1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. Nonetheless, local attackers with low privileges can exploit it, and because the vulnerability's scope is changed, the compromise could spread to other applications on the infrastructure.

Generated by OpenCVE AI on August 24, 2026 at 21:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply vendor patch for Oracle VM VirtualBox 7.2.14 or install a newer, patched version.
  • Limit local user privileges to the minimum necessary to run VirtualBox, ensuring proper access control consistent with CWE‑284.
  • Monitor the host for suspicious activity such as unexpected Box configuration changes or unauthorized process execution. Review logs regularly for indications of compromise.

Generated by OpenCVE AI on August 24, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Access Control Vulnerability in Oracle VM VirtualBox 7.2.14

Mon, 24 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Core Component in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-732

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Core Component in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-732

Thu, 20 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox 7.2.14 Enabling Full Compromise
Weaknesses CWE-732

Thu, 20 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox 7.2.14 Enabling Full Compromise
Weaknesses CWE-732

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Takeover of Oracle VM VirtualBox via Low-Privilege Attack
Weaknesses CWE-732

Wed, 19 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation and Takeover of Oracle VM VirtualBox via Low-Privilege Attack
Weaknesses CWE-732

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T03:56:26.661Z

Reserved: 2026-08-04T22:06:34.618Z

Link: CVE-2026-71126

cve-icon Vulnrichment

Updated: 2026-08-24T14:40:32.011Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:13.400

Modified: 2026-08-26T17:56:42.260

Link: CVE-2026-71126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:15:07Z

Weaknesses