Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Check for updates
AI Analysis

Impact

The vulnerability is a Resource Exhaustion flaw (CWE-400) that allows a low‑privileged attacker who can reach the VirtualBox host via Remote Desktop Protocol to cause the VirtualBox service to hang or crash repeatedly, resulting in a complete denial of service. The impact affects availability only, with no compromise of confidentiality or integrity reported.

Affected Systems

Oracle VM VirtualBox 7.2.16 on any host that exposes Remote Desktop Protocol access. Only the VirtualBox service is affected; other host services remain operational.

Risk and Exploitability

The CVSS Base Score of 5.3 indicates moderate risk. EPSS is below 1%, suggesting that exploitation with publicly available tools is unlikely at present. The vulnerability is not listed in CISA KEV. The exploit vector requires network access via RDP and a low privilege user on the target host, making it less likely to be leveraged by highly skilled adversaries but still a concern for environments where RDP is broadly exposed.

Generated by OpenCVE AI on September 21, 2026 at 18:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Verify if Oracle has released an updated version of VirtualBox that addresses this denial‑of‑service issue and upgrade to that version.
  • Restrict RDP access to the VirtualBox host to trusted administrators, enforce multi‑factor authentication, and eliminate low‑privileged accounts that can connect via RDP.
  • Deploy host‑based or network firewall rules and intrusion‑detection alerts to detect and block repeated RDP connection attempts that could trigger crashes.

Generated by OpenCVE AI on September 21, 2026 at 18:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Low-privileged Network Attacker Can Cause Denial of Service in VirtualBox via RDP

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284 CWE-400

Sun, 20 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title Low Privilege RDP Attack Leads to Denial of Service in Oracle VM VirtualBox 7.2.16
Weaknesses CWE-400

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Low Privilege RDP Attack Leads to Denial of Service in Oracle VM VirtualBox 7.2.16
Weaknesses CWE-400

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with network access via RDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T15:48:20.343Z

Reserved: 2026-09-08T21:49:12.407Z

Link: CVE-2026-87267

cve-icon Vulnrichment

Updated: 2026-09-18T13:49:11.283Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:15.370

Modified: 2026-09-23T13:53:23.463

Link: CVE-2026-87267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T18:45:18Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption