Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

This vulnerability in Oracle VM VirtualBox 7.2.16 allows a low‑privileged attacker that has logged onto the Windows host to take full control of the VirtualBox process, resulting in a compromise of the virtualization platform. The impact includes loss of confidentiality, integrity, and availability of all virtual machines, stemming from an improper access control flaw in the core component.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox version 7.2.16 on Windows hosts.

Risk and Exploitability

The CVSS 3.1 base score is 7.8, while the EPSS score of 0.00127 indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local and requires the attacker to have a user account on the Windows host. Successful exploitation leads to full takeover of VirtualBox without user interaction. Even with a low exploitation likelihood, the potential impact remains high, so the overall risk is considered moderate to high for systems running the affected version, especially where local users have elevated privileges.

Generated by OpenCVE AI on September 18, 2026 at 13:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle VM VirtualBox release that addresses this issue, 7.2.17 or later.
  • Restrict local user privileges on the host system, ensuring only trusted accounts can execute VirtualBox binaries.
  • Configure host firewall rules to limit external interaction with VirtualBox ports and disable unnecessary services that expose the virtualization environment.

Generated by OpenCVE AI on September 18, 2026 at 13:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Full VirtualBox Takeover

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269

Thu, 17 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Allowing Full VirtualBox Takeover
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T03:56:00.876Z

Reserved: 2026-09-08T21:49:12.408Z

Link: CVE-2026-87270

cve-icon Vulnrichment

Updated: 2026-09-17T12:49:33.333Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:15.700

Modified: 2026-09-23T13:53:05.023

Link: CVE-2026-87270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T13:45:09Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control