Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
Published: 2026-09-15
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (complete crash or hang)
Action: Patch Now
AI Analysis

Impact

A vulnerability in the core component of Oracle VM VirtualBox 7.2.16 allows a high‑privileged attacker who can log on to the host infrastructure to force the virtualization software to crash or hang repeatedly, effectively denying availability. The impact is limited to the VirtualBox instance but the scope change indicates that other dependent products could also be adversely affected by this failure. The weakness is a denial‑of‑service condition rather than a data breach or credential compromise.

Affected Systems

Affected systems are Oracle VirtualBox version 7.2.16. No other versions are listed as impacted; however, any installation of this exact product should be considered vulnerable until an update is applied.

Risk and Exploitability

The base CVSS score of 6.0 indicates a moderate severity, with local access (AV:L) and high privilege (PR:H) required for exploitation. The EPSS score of < 1% suggests that the likelihood of this vulnerability being actively exploited at this time is very low, and it is not listed in CISA’s KEV catalog. Nevertheless, because a successful exploit causes a complete denial of service, administrators should treat the risk as significant for environments where VirtualBox hosts are critical to operations. The attack vector is local and requires high privileges, so it is most relevant when an attacker has physical or administrative access to the host machine.

Generated by OpenCVE AI on September 18, 2026 at 17:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Oracle VirtualBox security patch that removes this vulnerability by upgrading to a newer version than 7.2.16.
  • Restrict local high‑privilege accounts and enforce the principle of least privilege so that only trusted administrators can start or manage VirtualBox instances.
  • Configure automated monitoring and re‑start policies to detect and recover from unexpected crashes, and consider isolating VirtualBox hosts from untrusted network zones.

Generated by OpenCVE AI on September 18, 2026 at 17:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Local Privilege DoS in Oracle VirtualBox 7.2.16

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Local Privilege DoS in Oracle VirtualBox 7.2.16
Weaknesses CWE-1035
CWE-400

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T14:11:30.457Z

Reserved: 2026-09-08T21:49:12.408Z

Link: CVE-2026-87283

cve-icon Vulnrichment

Updated: 2026-09-17T14:21:44.651Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:17.933

Modified: 2026-09-23T13:50:49.247

Link: CVE-2026-87283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T17:30:11Z

Weaknesses