Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists within the Core component of Oracle VM VirtualBox version 7.2.14, allowing an attacker who already possesses high privileged access to the host infrastructure to fully compromise the VirtualBox installation. The vulnerability is locally exploitable, requires no network access or user interaction, and can lead to complete loss of confidentiality, integrity, and availability of the VirtualBox service, with a potential scope change affecting additional products on the same host.

Affected Systems

Oracle VM VirtualBox 7.2.14, delivered as part of the Oracle Virtualization platform, is the only explicitly affected version listed in the advisory. No other product versions are currently identified as impacted.

Risk and Exploitability

The CVSS v3.1 base score of 8.2 indicates a high‑severity issue; the exploitability vector (AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H) reflects a local attack that requires a user to be already privileged. The EPSS score of < 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not catalogued in the CISA KEV list. Nevertheless, in environments where privileged users exist on the host running VirtualBox, the risk of a successful exploitation carries significant impact, potentially allowing the attacker to take full control over the VirtualBox service and affect other services due to the indicated scope shift.

Generated by OpenCVE AI on August 21, 2026 at 01:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Consult Oracle’s security advisories or product update channel for any patch that addresses VirtualBox 7.2.14’s core component flaw, and apply the update when available.
  • Apply the principle of least privilege by restricting high‑privileged user accounts on the host that runs VirtualBox, and consider running VirtualBox within an isolated or dedicated user session.
  • Isolate VirtualBox from other critical services by operating it in a segregated environment or dedicated host, and disable any unnecessary features or services that are not required for virtualization.

Generated by OpenCVE AI on August 21, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Enabling Full Takeover of Oracle VM VirtualBox

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Enabling Full Takeover of Oracle VM VirtualBox

Thu, 20 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox Core
Weaknesses CWE-284

Wed, 19 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox Core

Wed, 19 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-284

Wed, 19 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:59:28.925Z

Reserved: 2026-08-04T22:06:34.619Z

Link: CVE-2026-71129

cve-icon Vulnrichment

Updated: 2026-08-20T17:51:34.184Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:13.737

Modified: 2026-08-26T17:57:13.710

Link: CVE-2026-71129

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T02:00:05Z

Weaknesses