Junglewise Threat Intelligence

CVE-2026-47044: Oracle VM VirtualBox denial of service in Core component

CVE-2026-47044 · Severity: medium · CVSS 5.5 · Published 2026-07-21

Technologies: Oracle VirtualBox. Vendors: Oracle.

Executive brief

A vulnerability in Oracle VM VirtualBox, a popular virtualization platform, allows a user with low-level access to the host computer to crash the software. This can lead to a complete denial of service for any virtual machines running on that system. While it does not allow for data theft, it can disrupt business operations and service availability.

Technical details

A vulnerability in the Core component of Oracle VM VirtualBox version 7.2.12 allows for a local denial of service. An attacker with low-privileged access to the infrastructure where VirtualBox is executing can exploit this flaw to cause the application to hang or crash repeatedly. The attack is considered easily exploitable and does not require user interaction. The impact is limited to the availability of the VirtualBox service, with no reported impact on confidentiality or integrity. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.

Affected products

  • Oracle VM VirtualBox 7.2.12

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats