Junglewise Threat Intelligence

CVE-2026-60162: Oracle VM VirtualBox data exposure in Core component

CVE-2026-60162 · Severity: medium · CVSS 6.1 · Published 2026-07-21

Technologies: Oracle VirtualBox. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle VM VirtualBox, a software tool used to run multiple operating systems on a single computer. A highly privileged attacker with existing access to the host system could exploit this flaw to gain unauthorized access to sensitive data or cause a partial service disruption. Because this issue involves a 'scope change,' an attacker might be able to move beyond the virtual machine to impact the underlying host or other connected systems.

Technical details

A vulnerability in the Core component of Oracle VM VirtualBox version 7.2.12 allows a high-privileged attacker with local logon access to the host infrastructure to compromise the application. The exploit is characterized as difficult (High Attack Complexity) but results in a Scope change (S:C), meaning the impact can extend beyond the VirtualBox environment to the host or other products. Successful exploitation can lead to unauthorized access to all VirtualBox data (High Confidentiality impact) and a partial denial of service (Low Availability impact). No user interaction is required for this attack.

Affected products

  • Oracle VM VirtualBox 7.2.12

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60162
  • 2026-07-21: advisory: Oracle Critical Patch Update (CPU) July 2026 released

References

Related threats