Junglewise Threat Intelligence

CVE-2026-60161: Oracle VM VirtualBox denial of service in Core component

CVE-2026-60161 · Severity: medium · CVSS 6.1 · Published 2026-07-21

Technologies: Oracle VirtualBox. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle VM VirtualBox, a popular virtualization tool used to run multiple operating systems on a single computer. An attacker with local access to the system could trick a user into performing an action that causes the software to crash or stop responding, leading to a denial of service. Additionally, the attacker could gain unauthorized access to modify or delete certain data within the VirtualBox environment.

Technical details

A vulnerability in the Core component of Oracle VM VirtualBox version 7.2.12 allows an unauthenticated attacker with local logon access to the host infrastructure to compromise the application. The vulnerability is classified as easily exploitable but requires human interaction (UI:R) from a person other than the attacker. Successful exploitation can lead to a complete denial of service (hang or repeatable crash) and unauthorized integrity impacts, such as the ability to update, insert, or delete some VirtualBox accessible data. The attack vector is local (AV:L) with low complexity (AC:L).

Affected products

  • Oracle VM VirtualBox 7.2.12

Timeline

  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats