Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
Published: 2026-08-18
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Oracle VM VirtualBox 7.2.14 permits an attacker who has local high‑privileged access to the host to trigger a hang or repeated crash of the VirtualBox process, resulting in a complete denial of service of the virtualization platform. The vulnerability does not provide a path to arbitrary code execution or compromise confidentiality, but the availability impact can disrupt any services that rely on the host to run virtual machines.

Affected Systems

Oracle Corporation’s VirtualBox version 7.2.14 is affected. Because the CVSS vector indicates a scope change (S:C), the impact may extend to other software running on the same host, potentially affecting applications that depend on the virtualization layer.

Risk and Exploitability

The CVSS v3.1 score of 6.0 reflects a local attack with low complexity and high availability impact. The EPSS score of < 1% indicates an extremely low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the CVE vector, the likely attack vector is local access; the CVSS score and the description confirm that a high‑privileged attacker can induce a crash by interacting with VirtualBox. The scope change suggests that a successful exploit could impact additional products on the host, though no remote reachability is described.

Generated by OpenCVE AI on August 20, 2026 at 22:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle VM VirtualBox to a patched version when it becomes available.
  • Restrict local high‑privileged access to the host system to trusted administrators only, and monitor for suspicious activity that might trigger VirtualBox crashes.
  • Regularly reboot or restart the VirtualBox service after updates to ensure the patch is in effect and monitor for repeated crash patterns.

Generated by OpenCVE AI on August 20, 2026 at 22:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Local High-Privilege Attacker Can Induce Denial of Service in Oracle VM VirtualBox
Weaknesses CWE-400

Thu, 20 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Denial of Service Vulnerability in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-400

Thu, 20 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Denial of Service Vulnerability in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-400

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Denial of Service in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-400

Wed, 19 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Denial of Service in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-400

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T01:23:04.573Z

Reserved: 2026-08-04T22:06:34.619Z

Link: CVE-2026-71128

cve-icon Vulnrichment

Updated: 2026-08-25T01:22:13.461Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:13.623

Modified: 2026-08-26T17:56:57.870

Link: CVE-2026-71128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T23:00:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption