Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Compromise of Oracle VM VirtualBox that can lead to full takeover of the host environment
Action: Immediate Patch
AI Analysis

Impact

A vulnerability exists in the core component of Oracle VM VirtualBox that allows an attacker who has simply logged onto the same infrastructure to take control of the VirtualBox process. Because the vulnerability can be exploited locally without any pre‑existing authentication, it is considered easily exploitable, although the attacker still must interact with a user other than themselves to initiate the attack. When successfully exploited, the impact is severe, affecting confidentiality, integrity, and availability of the VirtualBox instance and potentially other applications that rely on it, as noted by the scope change.

Affected Systems

The affected product is Oracle VM VirtualBox version 7.2.16 from Oracle Corporation. No other vendors or product variants are listed as affected in the current advisory.

Risk and Exploitability

The CVSS base score is 8.6, indicating a high severity vulnerability. EPSS is reported as less than 1 %, meaning the probability of exploitation is currently very low but not zero. The vulnerability is not included in the CISA KEV catalog. Exploitation requires the attacker to have local logon access to the host machine where VirtualBox runs and a human interaction from a user other than the attacker to trigger the exploit. Because of its local nature and the need for user interaction, the immediate threat to environments with strict access controls is mitigated, but once those controls are bypassed, the potential for total compromise remains high. The scope change indicates that exploitation could spill over to other applications on the same host or connected virtual network. Overall, the risk remains high for any environment running Oracle VM VirtualBox 7.2.16 that exposes the host to local users.

Generated by OpenCVE AI on September 17, 2026 at 23:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest version of Oracle VM VirtualBox that contains the vendor‑issued fix.
  • Limit local logon access to trusted administrators only and monitor VirtualBox processes for unusual activity.
  • Disable or isolate unused VirtualBox services, enforce least‑privilege permissions, and segment virtual networks to contain any breach.

Generated by OpenCVE AI on September 17, 2026 at 23:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title Local Logon Vulnerability Allowing Complete VirtualBox Takeover
Weaknesses CWE-764
CWE-862

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Local Logon Vulnerability Allowing Complete VirtualBox Takeover
Weaknesses CWE-764
CWE-862

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-22T03:55:51.514Z

Reserved: 2026-09-08T21:49:12.408Z

Link: CVE-2026-87273

cve-icon Vulnrichment

Updated: 2026-09-17T12:55:43.056Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:16.023

Modified: 2026-09-23T13:52:37.683

Link: CVE-2026-87273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:00:13Z

Weaknesses
  • CWE-269

    Improper Privilege Management