Junglewise Threat Intelligence

CVE-2026-71116: Oracle VM VirtualBox privilege escalation in Core

CVE-2026-71116 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is a virtualization platform used to run multiple operating systems on a single computer. A high-privileged attacker with access to the host infrastructure can exploit a vulnerability in the Core component to take over VirtualBox and potentially compromise other systems running on it. This could lead to loss of data, service disruption, and compromise of all virtual machines under that host's control.

Technical details

A privilege escalation vulnerability exists in the Core component of Oracle VM VirtualBox version 7.2.14. The vulnerability is difficult to exploit and requires high-level privileges and local access (logon to the infrastructure where VirtualBox executes). Successful exploitation allows an attacker to achieve complete takeover of the VirtualBox system with impacts to confidentiality, integrity, and availability. The vulnerability has scope change, meaning an attack on VirtualBox can significantly impact additional products and systems. Patches are available from Oracle; users should update to the latest supported version.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats