Junglewise Threat Intelligence

CVE-2026-35275: Oracle VM VirtualBox improper access control in Shared Folders

CVE-2026-35275 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle VM VirtualBox, a popular tool used to run multiple operating systems on a single computer. An attacker with existing low-level access to the host computer could exploit the Shared Folders feature to gain unauthorized access to sensitive data or modify critical files. This could lead to a full compromise of the virtual environment and potentially impact the security of the underlying host system.

Technical details

An improper access control vulnerability (CWE-284) exists in the Shared Folders component of Oracle VM VirtualBox version 7.2.8. The flaw is categorized as difficult to exploit (AC:H) and requires the attacker to have local logon credentials with low privileges (PR:L). Successful exploitation results in a scope change (S:C), meaning the attacker can move beyond the virtualized environment to impact the host or other products. This allows for unauthorized creation, deletion, or modification of all data accessible to VirtualBox, as well as complete access to sensitive information. A fix is typically provided via Oracle's Critical Patch Update (CPU) program.

Affected products

  • Oracle VM VirtualBox 7.2.8

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats