Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a local access flaw (CWE-284) that allows an unauthenticated user who has already logged on to the host system to compromise Oracle VM VirtualBox. Successful exploitation can lead to the creation, deletion or modification of critical VirtualBox data, unauthorized reading of a subset of data, and the ability to trigger a partial denial of service. The CVSS vector (AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L) indicates moderate to high impact on confidentiality, integrity, and availability.

Affected Systems

Oracle VM VirtualBox version 7.2.14 is the only affected release. The likely impact on additional products is inferred from the scope change flag in the CVSS vector, but the primary target is the VirtualBox installation itself.

Risk and Exploitability

The estimated CVSS of 7.7 classifies the vulnerability as high severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting it is not a known widely exploited flaw yet. The requirement for local access and human interaction between the attacker and another party suggests that the likelihood of exploitation depends on the environment’s security controls, and in environments where privileged users have broad access to VirtualBox hosts, the risk is significant.

Generated by OpenCVE AI on August 20, 2026 at 17:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle VM VirtualBox patch or upgrade to a newer version that addresses the 7.2.14 flaw
  • Enforce least‑privilege for accounts that can run VirtualBox, limiting local access to the minimum necessary
  • Monitor VirtualBox logs for suspicious activity such as unauthorized file changes or partial service disruptions

Generated by OpenCVE AI on August 20, 2026 at 17:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Local Access Vulnerability in Oracle VM VirtualBox 7.2.14 Allows Data Manipulation and Partial Denial of Service

Thu, 20 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Local Access Vulnerability in Oracle VM VirtualBox 7.2.14 Allows Data Manipulation and Partial Denial of Service

Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Access Vulnerability Allowing Unauthorized Data Manipulation in Oracle VM VirtualBox
Weaknesses CWE-269

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Access Vulnerability Allowing Unauthorized Data Manipulation in Oracle VM VirtualBox
Weaknesses CWE-269
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:07.050Z

Reserved: 2026-08-04T22:06:34.620Z

Link: CVE-2026-71141

cve-icon Vulnrichment

Updated: 2026-08-19T12:08:56.065Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:15.017

Modified: 2026-08-25T19:03:36.523

Link: CVE-2026-71141

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T18:00:04Z

Weaknesses