Junglewise Threat Intelligence

CVE-2026-47054: Oracle VM VirtualBox privilege escalation in Core component

CVE-2026-47054 · Severity: high · CVSS 7.8 · Published 2026-07-21

Technologies: Oracle VirtualBox. Vendors: Oracle.

Executive brief

A vulnerability in Oracle VM VirtualBox allows a user with low-level access to the host computer to take full control of the virtualization software. This issue specifically affects Windows-based host systems. An attacker could exploit this to compromise the integrity of the virtual environment, potentially leading to unauthorized access to data or disruption of virtualized services.

Technical details

A vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.12. The flaw is categorized as easily exploitable and requires the attacker to have local logon credentials on the Windows host infrastructure where VirtualBox is running. Successful exploitation allows a low-privileged attacker to achieve a complete takeover of the Oracle VM VirtualBox instance, impacting confidentiality, integrity, and availability. This vulnerability is specific to Windows hosts and does not require user interaction. Details regarding the specific CWE or root cause were not disclosed in the initial advisory, but it is tracked under the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle VM VirtualBox 7.2.12

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats