Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-08-18
Score: 5.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle VM VirtualBox core component contains a vulnerability that allows a low‑privileged local user to compromise the VirtualBox runtime without user interaction. If an attacker has logon access to the host, they can read all data exposed by VirtualBox, making the breach a severe confidentiality risk while leaving integrity and availability unaffected. The CVSS 3.1 vector indicates a local attack with low privileges, no user interaction required, and a confidentiality impact rated high.

Affected Systems

Oracle VM VirtualBox version 7.2.14 installed on host systems is vulnerable. Because the flaw has a scope change property, attacks that succeed against VirtualBox can also affect any additional products that interact with VirtualBox.

Risk and Exploitability

The CVSS score of 5.6 labels this vulnerability as moderate. Exploitation requires only local access with low privileges and the attack requires no additional user interaction, suggesting a moderate risk of exploitation in environments where such users exist. The EPSS score is less than 1% and this issue is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 21, 2026 at 02:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Oracle VM VirtualBox release that contains the fix for version 7.2.14.
  • Restrict local user accounts on hosts running VirtualBox to prevent low‑privileged users from accessing the VirtualBox runtime.
  • Regularly audit VirtualBox configuration and logs to detect unauthorized changes or suspicious activity.

Generated by OpenCVE AI on August 21, 2026 at 02:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Local Unauthorized Data Access via VirtualBox Exploit

Thu, 20 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Local Unauthorized Data Access via VirtualBox Exploit

Thu, 20 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 20 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Local Privilege & Confidentiality Breach via VirtualBox Vulnerability
Weaknesses CWE-200
CWE-284

Thu, 20 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Local Privilege & Confidentiality Breach via VirtualBox Vulnerability
Weaknesses CWE-200
CWE-284

Wed, 19 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox Leading to Data Disclosure
Weaknesses CWE-269
CWE-862

Wed, 19 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox Leading to Data Disclosure
Weaknesses CWE-269
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.14. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.14:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T17:58:58.400Z

Reserved: 2026-08-04T22:06:34.620Z

Link: CVE-2026-71151

cve-icon Vulnrichment

Updated: 2026-08-20T17:47:37.584Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:18:16.167

Modified: 2026-08-25T19:03:55.127

Link: CVE-2026-71151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T02:45:04Z

Weaknesses