Junglewise Threat Intelligence

CVE-2026-60158: Oracle VM VirtualBox integrity and availability vulnerability in Core component

CVE-2026-60158 · Severity: medium · CVSS 6.4 · Published 2026-07-21

Technologies: Oracle VirtualBox. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle VM VirtualBox, a software tool used to run multiple operating systems on a single computer. A user with low-level access to the host computer could exploit this flaw to modify or delete critical data within the virtual environment. This could lead to data corruption or a partial disruption of services, potentially affecting other software running on the same system.

Technical details

A vulnerability in the Core component of Oracle VM VirtualBox (specifically version 7.2.12) allows a low-privileged attacker with local logon access to the host infrastructure to compromise the application. The exploit is characterized as difficult to perform (High Attack Complexity) but results in a scope change, meaning the impact can extend beyond VirtualBox to the underlying host or other virtualized products. Successful exploitation enables the unauthorized creation, deletion, or modification of critical data and can cause a partial denial of service. The vulnerability is tracked as CVE-2026-60158 and was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle VM VirtualBox 7.2.12

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.

References

Related threats