Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the core component of Oracle VM VirtualBox publicly allows an unauthenticated attacker with Remote Desktop Protocol network access to read critical data and perform update, insert or delete operations on VirtualBox‑exposed data. The flaw results in high confidentiality impact and lower integrity impact as outlined by the CVSS 3.1 vector, indicating that an attacker can not only observe sensitive information but also alter it. The weakness can be classified as improper access control.

Affected Systems

Oracle VM VirtualBox version 7.2.14 is specifically affected. No other versions or products are listed as impacted in the available data.

Risk and Exploitability

The CVSS base score of 8.2 classifies this as high‑severity. Exploitability is considered high because the attack requires only unprivileged network access with no user interaction and no local authentication. The EPSS score is reported as less than 1%, suggesting a relatively low probability of exploitation in the wild, yet the ease of exploitation described in the advisory indicates that successful attacks are plausible. The vulnerability is not listed in CISA’s KEV catalog, but the potential for unauthorized data access and modification makes it a serious threat if left unpatched.

Generated by OpenCVE AI on August 21, 2026 at 02:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle VM VirtualBox patch that addresses this issue.
  • Restrict network exposure of the RDP service by applying firewall rules or VPN access to trusted hosts only.
  • Disable the VirtualBox RDP feature if it is not required for operations.

Generated by OpenCVE AI on August 21, 2026 at 02:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unprivileged Remote Access via RDP in Oracle VM VirtualBox

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unprivileged Remote Access via RDP in Oracle VM VirtualBox
Weaknesses CWE-287

Thu, 20 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated RDP Remote Access Vulnerability in Oracle VM VirtualBox
Weaknesses CWE-287

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated RDP Remote Access Vulnerability in Oracle VM VirtualBox
Weaknesses CWE-287

Wed, 19 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated RDP Access in Oracle VM VirtualBox
Weaknesses CWE-287

Wed, 19 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated RDP Access in Oracle VM VirtualBox
Weaknesses CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T18:34:12.554Z

Reserved: 2026-08-04T22:06:34.619Z

Link: CVE-2026-71130

cve-icon Vulnrichment

Updated: 2026-08-20T18:10:57.113Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:13.853

Modified: 2026-08-26T17:57:20.013

Link: CVE-2026-71130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T02:45:04Z

Weaknesses