Junglewise Threat Intelligence

CVE-2026-60159: Oracle VM VirtualBox privilege escalation in Core component

CVE-2026-60159 · Severity: high · CVSS 7.5 · Published 2026-07-21

Technologies: Oracle VirtualBox. Vendors: Oracle.

Executive brief

A vulnerability in Oracle VM VirtualBox, a popular virtualization tool, could allow a highly privileged user on the host system to take complete control of the VirtualBox environment. While difficult to exploit, a successful attack could potentially impact other software running on the same infrastructure. This poses a risk to the confidentiality and integrity of virtualized workloads and the underlying host system.

Technical details

A vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.12. The flaw is characterized by a scope change (S:C), meaning a successful exploit can impact components beyond the immediate security scope of VirtualBox. The attack vector is local, requiring the attacker to have existing logon access to the infrastructure where VirtualBox is executing with high privileges (PR:H). Although the vulnerability is described as difficult to exploit (AC:H), a successful attack results in a complete takeover of the VirtualBox application, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle VM VirtualBox 7.2.12

Timeline

  • 2026-07-21: advisory: NVD publication date

References

Related threats