Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).
Published: 2026-09-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and Integrity Compromise
Action: Assess Impact
AI Analysis

Impact

A flaw in the Core component of Oracle VM VirtualBox 7.2.16 allows an attacker who is already logged on with low privileges to trigger a repeating cause a hang or frequently repeatable crash of VirtualBox, as well as unauthorized update, insert or delete access to some of VirtualBox accessible data. The vulnerability presents integrity and availability impacts, reflected in a CVSS Base Score of 6.1. The weakness is CWE-400.

Affected Systems

Oracle VM VirtualBox 7.2.16 running on any host where the user has low privileges and can log on to the infrastructure where VirtualBox executes.

Risk and Exploitability

The CVSS score indicates moderate risk. The EPSS score of < 1% suggests a very low probability of exploitation at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog access, but any logged‑on user with low‑privileged access can exploit this flaw through arbitrary operations within the VirtualBox process.

Generated by OpenCVE AI on September 22, 2026 at 18:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Oracle security patch or upgrade that addresses the core component flaw in VirtualBox 7.2.16 or upgrade to a newer supported version.
  • Restrict local user accounts on hosts running VirtualBox to administrators or explicitly authorized users to limit low‑privileged access.
  • Configure file system permissions or access control lists on VirtualBox configuration files to prevent unauthorized modification by non‑admin users.

Generated by OpenCVE AI on September 22, 2026 at 18:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Title Local Low‑Privilege Denial of Service and Integrity Compromise via Vulnerable Core Component in Oracle VM VirtualBox 7.2.16

Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Local Privileged User Can Cause VM Crash and Alter Data in VirtualBox 7.2.16

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Privileged User Can Cause VM Crash and Alter Data in VirtualBox 7.2.16

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploit Causing Denial of Service and Data Modification in Oracle VM VirtualBox 7.2.16
Weaknesses CWE-862

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 17 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploit Causing Denial of Service and Data Modification in Oracle VM VirtualBox 7.2.16
Weaknesses CWE-862

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T14:50:56.364Z

Reserved: 2026-09-08T21:49:12.408Z

Link: CVE-2026-87279

cve-icon Vulnrichment

Updated: 2026-09-17T14:21:55.871Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:16.680

Modified: 2026-09-23T13:51:36.813

Link: CVE-2026-87279

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T18:15:15Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption