Junglewise Threat Intelligence

CVE-2026-71115: Oracle VM VirtualBox data exposure in Core component

CVE-2026-71115 · Severity: medium · CVSS 6 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform that allows organizations to run multiple operating systems on a single physical computer. A flaw in the Core component allows a privileged user with local access to read sensitive data stored by VirtualBox or data accessible to virtual machines running on the host. This could expose customer data, credentials, or confidential information across multiple virtual environments.

Technical details

This is a local privilege escalation vulnerability in Oracle VM VirtualBox's Core component affecting version 7.2.14 and likely other 7.x releases. The vulnerability requires high-level privileges and local logon access to the infrastructure where VirtualBox runs. The attack vector is local (AV:L) with low complexity (AC:L), and successful exploitation results in high confidentiality impact with scope change—meaning an attacker can read critical data not only within VirtualBox but potentially on the host system and connected virtual machines. No public exploit code is currently known, and a patch status from Oracle is not yet confirmed.

Affected products

  • Oracle VM VirtualBox 7.2.14 (likely others in 7.x branch)

Timeline

  • 2026-08-18: disclosed

References

Related threats