Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).
Published: 2026-09-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and Denial of Service
Action: Update
AI Analysis

Impact

A flaw in Oracle VM VirtualBox 7.2.16 allows an unauthenticated local attacker who can log into the host system to compromise the VirtualBox process. The vulnerability can lead to unauthorized updates, inserts, or deletions of data accessed by VirtualBox and can cause the application to hang or repeatedly crash, representing a significant availability impact. The CVSS 3.1 vector indicates local attack with low complexity and no privileges, but user interaction is required, implying that the attacker must rely on another user to trigger the exploit.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox version 7.2.16 is the only product and version explicitly affected by this vulnerability.

Risk and Exploitability

The CVSS base score of 6.1 classifies this as a moderate severity flaw, while the EPSS score of less than 1% suggests a very low current exploitation probability. Because the exploit requires local access to a host where VirtualBox is installed, it is unlikely to be attacked remotely, but any compromised local account can be used to misconfigure VirtualBox or cause service interruptions. The vulnerability is not listed in the CISA KEV catalog, indicating no known large-scale exploitation yet.

Generated by OpenCVE AI on September 18, 2026 at 17:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Oracle VM VirtualBox to the latest available release that contains the fix for this issue.
  • Restrict local user permissions so that only trusted administrators can run VirtualBox and access its configuration files.
  • Enforce strict network segmentation and monitoring to detect abnormal VirtualBox crashes or data changes, and disable usage in environments where it is not required.

Generated by OpenCVE AI on September 18, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Oracle VirtualBox 7.2.16 Improper Access Leading to Denial of Service and Data Modification

Wed, 16 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Title Oracle VirtualBox 7.2.16 Improper Access Leading to Denial of Service and Data Modification
Weaknesses CWE-284
CWE-287
CWE-400

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:10:52.323Z

Reserved: 2026-09-08T21:49:12.408Z

Link: CVE-2026-87278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:16.570

Modified: 2026-09-23T13:51:43.470

Link: CVE-2026-87278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:30:11Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-400

    Uncontrolled Resource Consumption