Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).
Published: 2026-09-15
Score: 3.2 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Data Access
Action: Apply Patch
AI Analysis

Impact

Oracle VM VirtualBox 7.2.16 contains a flaw that allows an attacker with local administrative privileges on the host to read confidential data stored within the VirtualBox environment. The vulnerability arises from improper access control within the core component, enabling the attacker to bypass expected confines and access a subset of VirtualBox‑managed data. The impact is limited to confidentiality, with no direct integrity or availability consequences reported. The flaw stems from CWE-284, improper access control.

Affected Systems

Oracle Corporation’s Oracle VM VirtualBox 7.2.16 running on a host system exposed to local administrative users.

Risk and Exploitability

The CVSS v3.1 base score of 3.2 indicates a low‑severity risk, primarily affecting confidentiality and requiring local access (attack vector Local, low complexity). The EPSS score of less than 1 % signifies a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw leads to unauthorized read access and can impact additional products when VirtualBox is integrated with other services, any environment where privileged local accounts exist should treat the issue as a low‑severity but actionable threat.

Generated by OpenCVE AI on September 20, 2026 at 06:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official Oracle patch for VirtualBox 7.2.16 or upgrade to a newer, non‑affected release.
  • Restrict local administrative access on host machines, ensuring only trusted users can run VirtualBox.
  • Implement host isolation or network segmentation to limit the reach of compromised VirtualBox instances.

Generated by OpenCVE AI on September 20, 2026 at 06:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Read via Improper Access Control in Oracle VM VirtualBox 7.2.16

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Read Access Privilege Escalation in Oracle VM VirtualBox 7.2.16
Weaknesses CWE-285

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Local Read Access Privilege Escalation in Oracle VM VirtualBox 7.2.16
Weaknesses CWE-284
CWE-285

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 3.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-17T15:10:31.745Z

Reserved: 2026-09-08T21:49:12.408Z

Link: CVE-2026-87281

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:16.903

Modified: 2026-09-23T13:51:22.223

Link: CVE-2026-87281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:15:07Z

Weaknesses