Executive brief
A vulnerability in Oracle VM VirtualBox's core component allows a high-privileged user on the host system to compromise the virtualization software. An exploit requires interaction from another person and can lead to the total loss of system availability or the unauthorized modification of critical data. Because this affects the virtualization layer, the impact can extend beyond VirtualBox itself to other systems running on the same infrastructure.
Technical details
This vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.8. It is classified as a local attack requiring high privileges and user interaction from someone other than the attacker. The exploit results in a 'scope change' (S:C), meaning the attacker can impact components beyond the VirtualBox application itself. Successful exploitation allows for the unauthorized creation, deletion, or modification of all accessible data, as well as the ability to cause a persistent hang or crash (Denial of Service). The vulnerability is tracked under CVE-2026-47050 and was disclosed in the July 2026 Oracle Critical Patch Update.
Affected products
- Oracle VM VirtualBox 7.2.8
Timeline
- 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.