Junglewise Threat Intelligence

CVE-2026-47055: Oracle VM VirtualBox integrity compromise in Core component

CVE-2026-47055 · Severity: low · CVSS 3.2 · Published 2026-07-21

Technologies: Oracle VirtualBox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox, a widely used virtualization platform, contains a security vulnerability in its core component. A highly privileged attacker who already has access to the underlying computer system can exploit this to modify or delete data within the VirtualBox environment. While the direct impact is limited to data integrity, the exploit could potentially affect other software running on the same infrastructure.

Technical details

A vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.12. The flaw is classified as easily exploitable but requires the attacker to have high privileges and local logon access to the infrastructure where VirtualBox is executing. The vulnerability results in a scope change (S:C), meaning an exploit can impact components beyond the immediate security scope of VirtualBox. The primary impact is on integrity, allowing unauthorized update, insertion, or deletion of accessible data. No confidentiality or availability impact is reported. The issue was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle VM VirtualBox 7.2.12

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats