Junglewise Threat Intelligence

CVE-2026-71114: Oracle VM VirtualBox data access vulnerability in Core

CVE-2026-71114 · Severity: medium · CVSS 6 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is hypervisor software used to run virtual machines on corporate infrastructure. A vulnerability in its core component allows a privileged user with local access to read sensitive data stored in VirtualBox-managed virtual machines, potentially exposing customer data or internal systems running on affected infrastructure.

Technical details

The vulnerability is a data access flaw in the Core component of Oracle VM VirtualBox that requires high-level privilege and local logon to the host system. An attacker with administrative access can exploit this to read critical data accessible to VirtualBox, with scope change indicating potential impact on guest virtual machines and connected systems. The attack vector is local with no user interaction required. Patch availability information is not detailed in the advisory.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats