Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H).
Published: 2026-09-15
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Availability (Denial of Service)
Action: Patch ASAP
AI Analysis

Impact

The vulnerability enables a low‑privileged user with logged‑on access to the host running Oracle VM VirtualBox to initiate a crash of the virtualization engine. Once the fault is triggered through a user‑action, the VirtualBox process repeatedly hangs or exits, effectively denying service to all virtual machines and host applications that depend on it. This is a classic resource exhaustion flaw (CWE‑400).

Affected Systems

Oracle VirtualBox version 7.2.16 is affected. No other product versions were listed as vulnerable.

Risk and Exploitability

The CVSS score of 4.4 indicates a medium severity with a significant Availability impact. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild at the time of analysis. Attacks require low‑privileged local access and a human‑initiated action; the flaw can be used to disrupt the VirtualBox host service, which may impact many dependent virtual machines.

Generated by OpenCVE AI on September 18, 2026 at 17:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest Oracle VirtualBox patch (at least version 7.2.17).
  • Limit local user privileges on the host to only those required for VirtualBox operation.
  • Enforce strict access controls to the VirtualBox executables and configuration files.
  • Enable host firewall rules to prevent unauthorized scripts from invoking VirtualBox interfaces.
  • Monitor VirtualBox logs for repeat crash events and investigate suspicious activity.

Generated by OpenCVE AI on September 18, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Unauthorized Crash in Oracle VM VirtualBox

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Unauthorized Crash in Oracle VM VirtualBox
Weaknesses CWE-400

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T12:50:08.391Z

Reserved: 2026-09-08T21:49:12.408Z

Link: CVE-2026-87274

cve-icon Vulnrichment

Updated: 2026-09-17T12:41:08.679Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:16.133

Modified: 2026-09-23T13:52:31.290

Link: CVE-2026-87274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:30:11Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption