Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).
Published: 2026-08-18
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Core component of Oracle VM VirtualBox 7.2.14. It represents a CWE-284 (Access Control) flaw, allowing a local user with high privileges to cause a hang or repeatable crash, effectively denying availability. In addition, the attacker can update, insert, or delete data accessible to VirtualBox and read a subset of that data, compromising confidentiality and integrity.

Affected Systems

Affected systems are installations of Oracle VM VirtualBox version 7.2.14. Based on the description, it is inferred that the vulnerability may also affect other Oracle virtualization products because the flaw resides in the core component that is shared across multiple product lines. Any system running Oracle VM VirtualBox 7.2.14 is therefore at risk.

Risk and Exploitability

The CVSS base score of 7.3 indicates high severity. The attack requires a logged‑on local account with high privileges, as shown by the CVSS vector AV:L. It is inferred that remote exploitation is not publicly disclosed. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation. Nevertheless, the impact of a successful attack includes complete denial of service and unauthorized modification or disclosure of VirtualBox data, which could lead to further system compromise if the virtual machines are used for critical workloads.

Generated by OpenCVE AI on August 20, 2026 at 18:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s latest patch or upgrade to a fixed version of VirtualBox that contains the fix for CVE-2026-71136.
  • If an update is not yet available, restrict local accounts on systems running VirtualBox from executing the VirtualBox process or disable the Core component if possible.
  • Monitor system logs for repeated hang or crash events and verify that no unauthorized data changes have occurred; consider enabling audit trails on VirtualBox accessible data.

Generated by OpenCVE AI on August 20, 2026 at 18:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Denial of Service in Oracle VM VirtualBox 7.2.14

Thu, 20 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Denial of Service in Oracle VM VirtualBox 7.2.14

Thu, 20 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 19 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and DoS in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-264
CWE-770

Wed, 19 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and DoS in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-264
CWE-770

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T16:00:12.256Z

Reserved: 2026-08-04T22:06:34.619Z

Link: CVE-2026-71136

cve-icon Vulnrichment

Updated: 2026-08-19T15:00:43.785Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:14.440

Modified: 2026-08-26T17:57:51.167

Link: CVE-2026-71136

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:15:04Z

Weaknesses