Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local vulnerability in the Core component of Oracle VM VirtualBox 7.2.14 allows an attacker who has local presence on the host machine to obtain the privileges of the logged‑in user after a separate user interacts with the system. The flaw lets the attacker take full control of VirtualBox, potentially affecting the host’s confidentiality, integrity, and availability, and the vector label confirms that no privilege is required to launch the initial attack. Successful exploitation raises the attacker's authority to that of a normal local user, enabling further malicious activity on the host.

Affected Systems

Oracle VM VirtualBox version 7.2.14. No other versions or variants are listed as affected.

Risk and Exploitability

With a CVSS base score of 8.6, the issue is high severity, but its local attack surface and the need for user interaction result in a low EPSS (<1%) and no current listing in the CISA KEV catalog. The vulnerability can lead to a scope change, so an affected machine can become a vector for compromising other components, yet the likelihood of immediate exploitation remains modest without deliberate involvement of a second user.

Generated by OpenCVE AI on August 21, 2026 at 04:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a patched release of Oracle VM VirtualBox that contains the vendor fix for the Core component.
  • Restrict local accounts that can launch or manage VirtualBox instances to trusted administrators and consider disabling the program for non‑privileged users.
  • If VirtualBox is not required, uninstall or disable the service to remove the attack surface.
  • Implement runtime monitoring of VirtualBox activity and alert on unexpected changes in configuration or executed binaries.

Generated by OpenCVE AI on August 21, 2026 at 04:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Local Exploit Enables Full VirtualBox Compromise with User Interaction

Fri, 21 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title VirtualBox 7.2.14 Local Privilege Escalation to Full Compromise
Weaknesses CWE-269
CWE-732

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 20 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title VirtualBox 7.2.14 Local Privilege Escalation to Full Compromise
Weaknesses CWE-269
CWE-732

Thu, 20 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-269
CWE-732

Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-269
CWE-732

Wed, 19 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox 7.2.14 Leading to System Compromise
Weaknesses CWE-269
CWE-732

Wed, 19 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox 7.2.14 Leading to System Compromise
Weaknesses CWE-269
CWE-732

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:59:23.615Z

Reserved: 2026-08-04T22:06:34.619Z

Link: CVE-2026-71131

cve-icon Vulnrichment

Updated: 2026-08-20T17:51:37.566Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:13.967

Modified: 2026-08-26T17:57:29.270

Link: CVE-2026-71131

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T04:45:03Z

Weaknesses