Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-09-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a local privilege escalation (CWE‑269) in the Core component of Oracle VM VirtualBox 7.2.16. An attacker who has a low‑privileged account logged into the host system can exploit the flaw to take control of the VirtualBox process. This can lead to full compromise of the VirtualBox instance, giving the attacker the ability to read, modify, or delete any data handled by VirtualBox and to interfere with its normal operation. The impact is limited to the VirtualBox environment and does not extend to the entire host.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox 7.2.16 is affected. The Core component of this product is impacted. No other versions or component variants are listed in the vulnerability description.

Risk and Exploitability

The CVSS 3.1 base score of 7.8 indicates high severity. The EPSS score is below 1%, showing low likelihood of current widespread exploitation. Attackers must already have local access to the host and can bind to the Vulnerable VirtualBox instance. Because the vulnerability is local and requires low privileges, it affords a moderate to high risk for systems running VirtualBox with inadequate isolation, but the low EPSS suggests that exploitation is currently unlikely.

Generated by OpenCVE AI on September 20, 2026 at 06:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Oracle VM VirtualBox to version 7.2.17 or later to receive the vendor‑supplied fix.
  • If an upgrade cannot be performed immediately, run VirtualBox under an account that has the minimum necessary privileges and restrict the account’s local permissions.
  • Limit host accounts that can log in to the machine until virtualization can be updated, as the vulnerability requires an existing local logon for exploitation.

Generated by OpenCVE AI on September 20, 2026 at 06:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM VirtualBox 7.2.16 Core

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM
Weaknesses CWE-284

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle VM
Weaknesses CWE-269
CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T03:55:52.654Z

Reserved: 2026-09-08T21:49:12.408Z

Link: CVE-2026-87272

cve-icon Vulnrichment

Updated: 2026-09-17T12:49:25.447Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:15.917

Modified: 2026-09-23T13:52:45.483

Link: CVE-2026-87272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:00:08Z

Weaknesses
  • CWE-269

    Improper Privilege Management