Description
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
Published: 2026-09-15
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Immediately
AI Analysis

Impact

A privileged local attacker with high privileged access on a host running Oracle VM VirtualBox can exploit a flaw in the Core component to force the VirtualBox process to hang or crash. This vulnerability, classified as CWE-400, is easily exploitable and results in a complete denial of service by disrupting the availability of the VirtualBox service.

Affected Systems

The flaw affects Oracle VM VirtualBox version 7.2.16. No other specific product versions are listed, but the CVE notes that a scope change may impact additional related products.

Risk and Exploitability

The CVSS score of 6.0 reflects a moderate severity of the availability impact. The EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the attacker requires high privileged local access and the vector is local, the exploitation likelihood depends on the security of the deployment environment rather than on network exposure.

Generated by OpenCVE AI on September 21, 2026 at 16:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Oracle VM VirtualBox to a patched version that addresses this vulnerability.
  • If a patch is not yet available, remove or disable VirtualBox from the infrastructure or isolate the host and enforce strict least‑privilege controls for users with local access.
  • Monitor the host for abnormal hangs or crashes and alert on repeated service interruptions.

Generated by OpenCVE AI on September 21, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Denial-of-Service via Improper Access Control in Oracle VM VirtualBox 7.2.16

Mon, 21 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284 CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Denial-of-Service via Improper Access Control in Oracle VM VirtualBox 7.2.16

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Privileged Local Attacker in Oracle VM VirtualBox 7.2.16
Weaknesses CWE-400

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Privileged Local Attacker in Oracle VM VirtualBox 7.2.16
Weaknesses CWE-400

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).
First Time appeared Oracle
Oracle vm Virtualbox
CPEs cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle vm Virtualbox
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Oracle Vm Virtualbox
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-21T14:12:10.463Z

Reserved: 2026-09-08T21:49:12.409Z

Link: CVE-2026-87285

cve-icon Vulnrichment

Updated: 2026-09-17T14:21:40.563Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T20:19:18.450

Modified: 2026-09-23T13:53:50.460

Link: CVE-2026-87285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T16:45:18Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption