Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).
Published: 2026-08-18
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle VM VirtualBox 7.2.14 allows a high‑privileged attacker who has logged on to the host machine to manipulate VirtualBox internals, causing a hang or repeatedly crashing the application, and to perform unauthorized update, insert or delete operations, as well as read access to some of the data exposed by VirtualBox. This flaw is a local privilege escalation problem that can also lead to confidentiality and integrity impacts because the attacker may access or alter VirtualBox‑managed data. The weakness falls under improper access control and information exposure, consistent with recognized CWEs for unauthorized data modification and disclosure.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox version 7.2.14 is the only affected release noted in the publicly available information. No other version or build is listed as vulnerable in the CVE data.

Risk and Exploitability

The CVSS 3.1 base score of 7.3 indicates a high‑severity vulnerability that is exploitable from the local environment (attack vector Local, Privileges High, User Interaction None). Because the EPSS score is reported as < 1% and the vulnerability is not listed in the CISA KEV catalog, the current exploit probability is very low yet non‑zero, but the risk remains significant for systems running the affected VirtualBox instance, especially if unrestricted local accounts exist and the host is not well isolated. Successful exploitation would allow a user with local access to cause a denial of service and potentially access or modify confidential data stored by VirtualBox.

Generated by OpenCVE AI on August 20, 2026 at 17:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle VM VirtualBox to a version that includes the fix for CVE‑2026‑71138
  • Restrict local user privileges on the host to only necessary accounts and disable unnecessary VirtualBox features that depend on the vulnerable code
  • Continuously monitor VirtualBox logs for repeated crashes or anomalous data modification activity and investigate any suspicious events promptly

Generated by OpenCVE AI on August 20, 2026 at 17:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Denial of Service in Oracle VM VirtualBox 7.2.14

Wed, 19 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Denial of Service in Oracle VM VirtualBox 7.2.14

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Denial of Service in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-200
CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Denial of Service in Oracle VM VirtualBox 7.2.14
Weaknesses CWE-200
CWE-284
CWE-400

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T14:45:25.313Z

Reserved: 2026-08-04T22:06:34.619Z

Link: CVE-2026-71138

cve-icon Vulnrichment

Updated: 2026-08-19T14:26:23.927Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:14.677

Modified: 2026-08-26T17:58:01.010

Link: CVE-2026-71138

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T17:15:04Z

Weaknesses