Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
Published: 2026-09-15
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Availability Disruption)
Action: Patch If Available
AI Analysis

Impact

The flaw resides in the Core component of Oracle VM VirtualBox and can be triggered by a local user with high privileges, causing the hypervisor to hang or crash, which results in a complete denial of service that affects the availability of virtual machines and any applications running inside them. The bug is a classic denial‑of‑service condition arising from improper resource management (CWE‑400). The potential impact is limited to availability; confidentiality and integrity are not affected.

Affected Systems

Oracle VM VirtualBox version 7.2.16 is listed as the affected release by the vendor; no other versions are explicitly marked as vulnerable in this CVE.

Risk and Exploitability

The CVSS base score of 6.0 indicates a moderate security impact focusing on availability, and the vector description (AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H) shows that the vulnerability requires local, authenticated access with high privileges. Based on the description, it is inferred that the attack vector is local. The EPSS score of less than 1% suggests that the problem is unlikely to be widely exploited at present, and the vulnerability is not in CISA’s KEV catalog. However, if a host is already compromised or an administrator account is abused, the flaw can be exercised with minimal effort, making the risk high for locally privileged systems.

Generated by OpenCVE AI on September 21, 2026 at 17:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any available vendor patch for VirtualBox or upgrade to a non‑vulnerable release.
  • Restrict local administrator privileges on hosts that run VirtualBox to reduce the attack surface.
  • Monitor VirtualBox logs for hangs or crashes and isolate affected machines; if a fix is not available, uninstall VirtualBox on exposed systems until the vulnerability is remediated.

Generated by OpenCVE AI on September 21, 2026 at 17:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Local Privileged Denial of Service in Oracle VM VirtualBox 7.2.16

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284 CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Local Privileged Denial of Service in Oracle VM VirtualBox 7.2.16

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Denial of Service in Oracle VM VirtualBox 7.2.16
Weaknesses CWE-400

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title Denial of Service in Oracle VM VirtualBox 7.2.16
Weaknesses CWE-400

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T14:11:11.199Z

Reserved: 2026-09-08T21:49:12.408Z

Link: CVE-2026-87282

cve-icon Vulnrichment

Updated: 2026-09-17T14:21:46.918Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:17.023

Modified: 2026-09-23T13:51:07.170

Link: CVE-2026-87282

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T17:45:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption