Junglewise Threat Intelligence

CVE-2026-60160: Oracle VM VirtualBox information disclosure in Core component

CVE-2026-60160 · Severity: low · CVSS 3.2 · Published 2026-07-21

Technologies: Oracle VirtualBox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox, a popular virtualization software used to run multiple operating systems on a single computer, contains a security vulnerability in its core component. A highly privileged user already logged into the host system can exploit this flaw to gain unauthorized access to certain data. While the direct impact is limited to reading specific information, the breach could potentially affect other software running on the same infrastructure.

Technical details

A vulnerability in the Core component of Oracle VM VirtualBox version 7.2.12 allows for an information disclosure. The flaw is classified as an unauthorized read access vulnerability that can be exploited by a high-privileged attacker with local logon access to the host infrastructure. The exploit is characterized by a 'scope change' (S:C), meaning the impact can extend beyond the VirtualBox environment to the underlying host or other guest systems. The attack requires no user interaction and has low complexity, though it requires high administrative privileges to execute. Oracle has addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle VM VirtualBox 7.2.12

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed: CVE-2026-60160 was publicly released.

References

Related threats