Junglewise Threat Intelligence

CVE-2026-71125: Oracle VM VirtualBox denial of service in Core

CVE-2026-71125 · Severity: medium · CVSS 6.1 · Published 2026-08-18

Technologies: Oracle Vm Virtualbox. Vendors: Oracle.

Executive brief

Oracle VM VirtualBox is virtualization software that allows users to run multiple operating systems on a single computer. A vulnerability in the Core component allows a local attacker with system access to crash the virtualization platform or corrupt data, disrupting virtual machine operations and potentially causing data loss.

Technical details

This is an easily exploitable local vulnerability in the Core component of Oracle VM VirtualBox 7.2.14 that requires user interaction to trigger. The vulnerability allows an unauthenticated attacker with local system access to cause denial of service (system hang or crash) and unauthorized modification or deletion of VirtualBox data. The attack vector is local (AV:L), no elevated privileges are required (PR:N), and user interaction is necessary (UI:R). Successful exploitation results in high availability impact and some integrity impact, with no confidentiality impact. Patches are expected from Oracle.

Affected products

  • Oracle VM VirtualBox 7.2.14

Timeline

  • 2026-08-18: disclosed

References

Related threats