Executive brief
Oracle VM VirtualBox, a popular virtualization tool used to run multiple operating systems on a single computer, contains a security vulnerability in its core component. An attacker who already has basic access to the host computer can exploit this flaw to take full control of the VirtualBox application. This could lead to unauthorized access to virtual machines, data theft, or disruption of virtualized services.
Technical details
A vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.12. The flaw is classified as easily exploitable and requires the attacker to have local logon credentials to the infrastructure where VirtualBox is executing. Successful exploitation allows a low-privileged attacker to achieve a complete takeover of the Oracle VM VirtualBox environment, impacting confidentiality, integrity, and availability. The attack vector is local (AV:L) with low complexity (AC:L) and no user interaction required (UI:N). While the specific CWE was not disclosed in the advisory, the impact is a full application compromise.
Affected products
- Oracle VM VirtualBox 7.2.12
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle via the July 2026 CPU.
- 2026-07-21: advisory: NVD published the CVE record.