Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:L).
Published: 2026-09-15
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access and partial denial of service
Action: Apply patch
AI Analysis

Impact

The flaw resides in the core component of Oracle VM VirtualBox 7.2.16 and can be exploited by an attacker who has logged onto the host system. This local attack, which requires high privileges, permits the attacker to read a subset of data available to VirtualBox and to trigger a partial denial of service that causes the hypervisor to become unresponsive or restart. While the vulnerability is confined to VirtualBox, the scope change noted in the description implies that additional products interacting with the hypervisor could also be affected.

Affected Systems

Oracle Corporation’s VirtualBox version 7.2.16 is affected; other versions are not listed as vulnerable.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation in current environments. The vector indicates a local attack requiring high privileges. Successful exploitation leads to unauthorized data reading and a partial service outage for VirtualBox, with the potential to impact other products that rely on the hypervisor due to the scope change.

Generated by OpenCVE AI on September 18, 2026 at 16:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Oracle VM VirtualBox 7.2.17 or later where the issue is fixed
  • If an upgrade is not feasible, restrict access to the host to trusted users only and consider removing or disabling VirtualBox where it is not essential
  • Monitor host logs for unexpected virtual machine activity and apply configuration hardening to limit VM visibility

Generated by OpenCVE AI on September 18, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title VirtualBox 7.2.16 Authorization Bypass and Partial DoS

Thu, 17 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Title VirtualBox 7.2.16 Authorization Bypass and Partial DoS
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:L).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:L'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:11:05.257Z

Reserved: 2026-09-08T21:49:12.408Z

Link: CVE-2026-87275

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:16.243

Modified: 2026-09-23T13:52:19.283

Link: CVE-2026-87275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:00:13Z

Weaknesses